← Back to blog

Chrome and Edge Extensions Caught Stealing Crypto Wallets

Researchers found 19 malicious browser extensions designed to steal cryptocurrency wallets. These extensions targeted users through deceptive downloads and code injection.

TL;DR

  • 19 malicious browser extensions (18 Chrome, 1 Edge) were found stealing crypto wallets.
  • Extensions used similar code patterns and were published within the last six months.
  • Attackers injected malicious scripts to capture sensitive wallet credentials.
  • Security firm Socket identified the campaign and disclosed the affected extensions.
  • Organizations should audit browser extension usage and monitor for suspicious behavior.

Cybersecurity researchers have uncovered a coordinated campaign involving 19 browser extensions—18 for Google Chrome and one for Microsoft Edge—that were designed to steal cryptocurrency wallet secrets. These extensions, published over the past six months,伪装成合法工具,诱使用户安装并泄露敏感凭证。

The malicious activity was detected by security researcher Karlo Zanki from Socket, who noted significant overlaps in code structure and attack techniques across the extensions. Once installed, these extensions injected scripts capable of capturing wallet authentication data and draining funds without user knowledge.

How the Attack Worked

  • The extensions mimicked legitimate tools to gain user trust and avoid detection.
  • They injected JavaScript into web pages to intercept wallet interactions.
  • Sensitive data like private keys and seed phrases were exfiltrated to attacker-controlled servers.
  • Code similarities suggest a single group orchestrated the campaign.

Protecting Your Organization

  • Audit all installed browser extensions, especially those with broad permissions.
  • Monitor network traffic for unexpected outbound connections from browsers.
  • Implement endpoint detection and response (EDR) solutions to catch script-based attacks.
  • Educate employees on the risks of third-party browser extensions.
  • Use allowlists to restrict which extensions can be installed company-wide.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.