Перейти к содержанию

Chrome extension can empty crypto wallet: Russians warned of new threat

Users of Binance, Bybit, OKX, MetaMask, Ledger, and other crypto services are at risk

Even a familiar extension from the official browser store can unexpectedly become dangerous. Socket specialists have discovered 18 malicious add-ons for Google Chrome and one for Microsoft Edge that are capable of stealing cryptocurrency, passwords, and other user data.

Image source: ChatGPT

The most unpleasant part is that some of the programs initially worked normally. According to researchers, at least five extensions were acquired by attackers from previous developers, and malicious code was added later through automatic updates. One of them – Enable Right Click & Copy – Smart Unlock + OCR – was installed by more than 80,000 Chrome and Edge users.

After infection, the extension gains the ability to interfere with pages directly within the browser. It can replace the crypto wallet connection button, show a fake Ledger or Trezor page, and attempt to steal the seed phrase. Users of Binance, Bybit, OKX, Coinbase, MetaMask, and other crypto services are also at risk.

The danger is also relevant for Russian users: such an add-on works inside the browser itself and can intercept data regardless of which country a person accesses the crypto exchange from. In addition to cryptocurrency, malware can collect entered passwords and browsing history.

By September 3, the discovered add-ons had already been removed from the Chrome Web Store, but experts still advise checking the list of installed extensions. If a compromised one was among them, it is better to consider passwords compromised and change them, and transfer cryptocurrency from associated wallets to new addresses.

The main conclusion here is simple: even an extension that has not caused suspicion for years should be periodically re-checked – its owner and the content of updates can change without the user's knowledge.

Read more on the topic: