By Interestana AI Editorial — AI-drafted, human-overseen. How we report
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Cybersecurity researchers have identified a significant cluster of 19 malicious browser extensions, comprising 18 for Google Chrome and one for Microsoft Edge, that were covertly designed to steal cryptocurrency wallet secrets and drain user funds. These extensions were published and made available to users over the last six months, a timeframe indicating a relatively recent but potentially widespread campaign. According to Karlo Zanki, a security researcher at Socket, the firm that conducted the investigation, these extensions exhibit striking similarities in their underlying code and operational tradecraft. This shared methodology strongly suggests that they are part of a coordinated and potentially ongoing malicious campaign orchestrated by a single threat actor or a closely aligned group.
The modus operandi of these malicious extensions involved injecting malicious JavaScript code into legitimate websites that users visited. This injected code was designed to actively monitor user activity for any cryptocurrency-related operations. Specifically, it would look for instances where users accessed their digital wallets, initiated cryptocurrency transactions, or interacted with decentralized applications (dApps) that handle digital assets. Upon detecting such activity, the malware would then attempt to exfiltrate highly sensitive information. This sensitive data includes critical credentials such as private keys or seed phrases, which are the ultimate keys to accessing, controlling, and transferring cryptocurrency holdings. The ultimate objective of this sophisticated scheme was to gain unauthorized access to users' digital wallets and illicitly transfer their cryptocurrency assets to attacker-controlled addresses, effectively stealing their digital wealth.
While the precise number of users affected by this campaign and the total monetary value of the cryptocurrency stolen have not yet been publicly disclosed by Socket or other security entities, this discovery underscores a persistent and evolving threat vector within the cryptocurrency ecosystem. Browser extensions, by their very nature, are granted significant access to a user's web browsing activity and the content displayed on web pages. This broad access makes them powerful tools for legitimate functionality, enhancing user experience and productivity. However, it also renders them a prime target for malicious exploitation, allowing attackers to intercept sensitive data or manipulate web content. The researchers' findings serve as a critical reminder of the paramount importance of rigorous security vetting processes for all browser extensions before they are made available to the public, and the imperative for users to exercise extreme caution and due diligence when installing any extension, particularly those that request extensive permissions or handle sensitive financial information.
The observed sophistication of this campaign, evidenced by the shared code and consistent tradecraft, points towards a potentially well-resourced and organized threat actor. The analysis conducted by Socket's researchers indicated evidence suggesting that this campaign may have been active for a considerable period before its detection, potentially compromising a significant number of users and their digital assets. This discovery acts as a stark and timely reminder of the ongoing and multifaceted risks associated with managing digital assets in the current threat landscape, and the continuous evolution of cyber threats specifically targeting cryptocurrency users. Further in-depth investigation is anticipated to fully ascertain the scope of this campaign, identify all compromised extensions, and assist affected users and platforms in mitigating the damage and preventing future occurrences.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.