Socket Finds 19 Malicious Browser Extensions Stealing Ethereum (ETH) Wallet Secrets

Security firm Socket uncovered 19 malicious Chrome and Edge extensions stealing crypto wallet secrets; Chrome copies were removed, the Edge variant stayed live.

(09:33 PM UTC)
4 min read
AI SummaryAI
  • Socket identified 19 malicious browser extensions targeting crypto wallet secrets across Chrome and Edge.
  • Socket estimates the campaign may date back to February 2024.
  • The most dangerous extension had about 70,000 Chrome users and 10,000 Edge users when weaponized.
  • The malware harvested sessions from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit and MetaMask.
k7rq2fdm

19 Extensions, Six Months of Activity

A cybersecurity research firm has uncovered a large-scale attempt to drain self-custody users through their own browsers. Socket, a company that monitors extension marketplaces for malicious code, has identified 19 add-ons for Google Chrome and Microsoft Edge built to steal cryptocurrency wallet secrets. According to the firm's report, 18 of the malicious extensions targeted Chrome users and one targeted Edge, and every one of them was published or weaponized at some point during the past six months. Socket's analysts believe the operation may stretch as far back as February 2024, which would mean the campaign ran undetected for well over two years. Extensions run with broad permissions inside the browser, so once one turns hostile it can read and modify almost everything a user does online — which is what makes this class of compromise so severe. The distribution method is notable for how ordinary it looked. In several cases the attackers wrote extensions that appeared entirely legitimate, complete with genuinely useful features that earned real adoption. In others they purchased existing, reputable extensions from their original developers and introduced malicious functionality later — a supply-chain pattern that exploits the trust users place in an established listing. Of the 19 extensions identified, 14 were authored by the threat actor itself and five were bought from legitimate developers. The most dangerous entry in the set was an add-on named “Enable Right Click & Copy — Smart Unlock + OCR.” Socket reported that the Chrome version had roughly 70,000 users at the moment its malicious functionality was switched on, while a companion Edge build carried about 10,000. The Chrome versions have since been removed from the Chrome Web Store, but the Edge variant was still downloadable when the report was published, meaning users on Microsoft's browser remained exposed after the cleanup on Google's side.

Wallet Drainers and Fake Ledger Pages

The capabilities documented in the report go well beyond simple credential theft. Socket's researchers found that the malware strips Content Security Policy protections from websites — the browser-level defense that restricts which scripts a page is allowed to execute — effectively opening trusted domains to script injection. At the core of the campaign sits a multi-chain wallet drainer targeting EVM-compatible wallets, Solana and Tron. The module tampers with legitimate “Connect Wallet” and “Swap” buttons on decentralized applications, redirecting users into attacker-controlled transaction flows while the interface looks unchanged. Because the drainer reuses the application's own UI elements, the redirect is difficult to spot even for experienced users. Hardware-wallet holders face a parallel vector: the malware serves convincing fake Ledger and Trezor recovery and update pages designed to trick victims into typing their seed phrases — a direct reminder that a Ledger recovery key should never be entered on any web page, no matter how authentic it appears. A separate family of modules harvests authenticated sessions and account information from centralized platforms, including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin and Bybit, alongside the MetaMask wallet. Session hijacking of that kind can hand an attacker access to an exchange account without ever touching a password, since stolen cookies inherit an already-verified login. The campaign also reaches past crypto entirely: additional modules target Facebook and LinkedIn accounts, steal browsing history and deploy ClickFix-style fake browser-update pages. The full list of indicators of compromise is laid out in Socket's technical breakdown of the wallet-drainer campaign. The firm's guidance to users is direct: audit installed browser extensions regularly and remove anything suspicious or no longer in use. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

Extension Hygiene as First Defense

The thread running through this story is that the browser itself has become a first-order attack surface for digital assets. A holder can spread funds across Bitcoin DeFi positions, EVM wallets and centralized exchange accounts, yet a single weaponized extension with 70,000 installs can reach all of them at once. The fact that the Edge version was still live while its Chrome counterparts had already been pulled shows how uneven marketplace enforcement remains. Until store-level review catches up, extension hygiene — fewer add-ons, verified publishers, regular audits — remains the cheapest security control a crypto user has.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.