Chrome Expansion Found to Have Stolen Encrypted Wallets
2026-08-29 04:44:44
According to CoinMeta, cybersecurity researchers have discovered 19 malicious browser extensions that steal from encrypted wallets, of which 18 are Google Chrome extensions and 1 is a Microsoft Edge extension. These extensions were released or weaponized over the past six months, possibly dating back to February 2024. It was found that 14 of the 19 extensions were created by threat actors, while 5 were purchased from legitimate authors. The most dangerous extension, "Enable Right-Click Copy—Smart Unlock + OCR," had approximately 70,000 users when the Chrome version introduced malicious functionality, and around 10,000 users in the Edge version. The Chrome extension has been removed from the store, but the Edge version is still in use. The malware was also found to remove website content security policies and includes multi-chain theft tools targeting EVM, Solana, and Tron wallets. The malware tampered with the "Connect Wallet" and "Exchange" buttons, redirecting users to attacker-controlled transaction processes, and displayed fake Ledger and Trezor pages to trick users into entering their mnemonic phrases. Socket recommends that users regularly check and remove suspicious extensions.
Bullish 0
Bearish 0
Source:U.Today
This content is for market information only and does not constitute investment advice.