A discussion has unfolded on the Bitcointalk forum regarding the SamFW Tool utility, which, according to victims' claims, contains hidden malware aimed at stealing cryptocurrency. At the same time, project representatives deny the accusations of an intentional scam, shifting the situation into a conflict with unproven financial claims.
According to user craftyart1010, after installing the SamFwToolSetup_v5.4.zip file on his computer, which stored 10,000 XMR (around $3 million) in a Feather Wallet hot wallet, the funds were rapidly withdrawn by attackers, and all data on the device was destroyed. He claims that the utility's developer intentionally injects Remote Access Trojans (RATs) into specific versions of the program and then removes them after the theft.
However, the program's developer, posting on the forum under the nickname tungtata, categorically rejected the hacking accusations. According to him, antivirus triggers on his programs are false positives related to the specific nature of low-level code for unlocking Android devices. He also expressed a willingness to provide the source code for an independent audit and emphasized that the accuser did not provide any technical proof of the theft, such as a TXID (transaction hash) or the wallet address from which the funds were allegedly stolen.
Despite the lack of evidence for the $3 million theft itself, a technical analysis of the utility's files confirmed a real threat. According to user albon, scanning the installer on VirusTotal revealed heuristic malware detections and a suspicious timestamp set to the year 2097. According to user escrow.ms, an independent analysis on the Hybrid-Analysis platform showed that the program is capable of modifying token privileges, terminating processes, and writing data to remote processes. According to user marto25, a senior research engineer from Malwarebytes officially confirmed the presence of a Trojan.Dropper in the utility, which is used to secretly install other malicious modules, including infostealers.

Furthermore, forum users criticized the author of the complaint for a gross violation of cybersecurity rules. According to user NotATether, storing such huge amounts on a computer connected to the internet, let alone running dubious software on it without checking it in an isolated environment, is an unacceptable mistake. According to user albon, the fact that the user did not have backups of the seed phrase and cannot provide the wallet address for verification on the blockchain makes his story about losing exactly $3 million highly questionable.
The situation surrounding SamFW Tool appears twofold. On the one hand, technical expertise confirms that the program does indeed contain malicious code (Trojan.Dropper) and is dangerous for users storing confidential data on their PCs. On the other hand, the specific story of user craftyart1010 regarding the theft of 10,000 XMR has no confirmation on the blockchain and appears unfounded. Users are strongly advised to avoid installing this software on primary devices.
source
https://bitcointalk.org/index.php?topic=5586649.0
Trust Rating