BNB $688.91 -2.95%
XRP $1.38 -5.00%
ETH $2,430.84 -2.82%
BTC $77,470.97 -3.27%
BNB $688.91 -2.95%
XRP $1.38 -5.00%
ETH $2,430.84 -2.82%
BTC $77,470.97 -3.27%
BREAKING
Crypto Exchanges

80,000 Crypto Users Targeted by 19 Malicious Browser Extensions in Chrome and Edge

19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge
19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge

Community Trust ScoreVerified

93%
Real
Verified14 votes
Updated 5 hours ago

Crypto wallets are getting drained. Quietly, methodically, and at scale — through something most users never think twice about: browser extensions.

Cybersecurity firm Socket uncovered a campaign built around 19 malicious browser extensions, 18 targeting Google Chrome and one targeting Microsoft Edge. The operation has been active for roughly six months, with signs it probably kicked off around February 2024. Socket’s researchers found that 14 of the 19 extensions were built from scratch by the threat actors. The other five? Legitimate extensions that developers had already published — acquired and then weaponized. That second category is the harder one to catch. Users who installed those extensions before they turned malicious had no obvious reason to suspect anything.

The biggest single extension in the bunch had about 70,000 users.

Advertisement

That’s “Enable Right Click & Copy — Smart Unlock + OCR,” which Socket flagged as the most dangerous extension in the campaign. Chrome pulled it from the Web Store. But the Microsoft Edge version of the same extension — roughly 10,000 users — remains active as of the time Socket published its findings. No details yet on when or whether Edge plans to remove it.

How the Wallet Drainer Actually Works

The technical setup is pretty sophisticated. Socket’s researchers found a multi-chain cryptocurrency wallet drainer embedded in the extensions. It targets EVM-compatible wallets, Solana wallets, and Tron wallets — so it’s not limited to one chain or one type of user. The malware can manipulate legitimate “Connect Wallet” and “Swap” buttons that users click on DeFi platforms every day, quietly redirecting the transaction flow toward attacker-controlled processes. You think you’re swapping tokens. You’re not.

Hardware wallet users aren’t safe either. The campaign includes fake recovery and update pages designed to look like official Ledger and Trezor interfaces. The goal is straightforward: get the user to enter their seed phrase. Once the attackers have that, the wallet is gone.

And the reach goes wider than just DeFi buttons and hardware wallet tricks. The extensions include modules built to harvest authenticated session data and account credentials from a long list of major platforms: Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. That’s basically a who’s-who of crypto infrastructure. If a user is logged into any of those while running a compromised extension, their session data is probably at risk.

One of the more technically alarming pieces is what Socket said about Content Security Policy protections. These extensions can strip CSP headers from websites, which basically tears down one of the core browser-level defenses against malicious scripts. Scripts that would normally get blocked can now run. That’s a significant escalation — it’s not just stealing data, it’s creating an open door for further exploitation.

Social Media Accounts Also in the Crosshairs

Crypto isn’t the only target. The campaign also goes after Facebook and LinkedIn accounts. Modules designed to compromise those accounts are baked into the same extensions. Whether the goal is to harvest personal data, use the accounts to spread more malware, or both — unclear. But the presence of social media targeting makes the campaign broader than a pure crypto play.

There’s also a ClickFix-style component. Fake browser-update pages that mimic legitimate Chrome or Edge update prompts push users to download additional malware. It’s a well-worn social engineering trick, but it works, especially when users are already running an extension that’s quietly manipulating what they see on-screen. The fake update pages add another layer of confusion, making it harder to figure out where the compromise actually started.

Browsing history is also being harvested. That data can be used to build profiles, identify which crypto platforms a user frequents, and tailor further attacks accordingly.

What Socket Says Users Should Do

Socket’s advice is direct: regularly audit your browser extensions. Remove anything that looks suspicious or that you don’t actively use. It’s not a glamorous fix, but it’s practical. Extensions accumulate over time — people install them for a specific task and forget about them. That’s exactly the kind of low-attention surface the attackers are exploiting.

Beyond extension audits, Socket warns users to be skeptical of any unexpected browser update prompts. Legitimate updates don’t typically come through pop-ups asking you to download something. If a page is pushing a browser update, that’s worth pausing on.

For hardware wallet users specifically, the fake Ledger and Trezor pages are the sharpest risk. Seed phrases should never be entered into any browser-based interface, period. Official recovery processes for those devices don’t happen in a Chrome tab.

The Chrome version of “Enable Right Click & Copy — Smart Unlock + OCR” is down. The Edge version, with its 10,000 users, is still up.

Frequently Asked Questions

Which browser extension was identified as the most dangerous in this campaign?

“Enable Right Click & Copy — Smart Unlock + OCR” was flagged as the most dangerous extension, with around 70,000 users on Chrome before removal and approximately 10,000 users on Microsoft Edge, where it remains active.

Which crypto platforms were targeted by the malicious extensions?

The extensions included modules targeting Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask, harvesting authenticated session data and account credentials from users on those platforms.

Why It Matters

This incident highlights the ongoing vulnerabilities within the cryptocurrency ecosystem, particularly as users increasingly rely on browser extensions for wallet management and transactions. The scale of the attack, affecting a significant number of users, underscores the importance of cybersecurity awareness and the need for robust protective measures in a market that remains a target for malicious actors. As trust in digital finance continues to be paramount, such breaches could hinder broader adoption of cryptocurrency technologies.

Community Trust IndexModerate Confidence
93%
Real
Real93%7%Fake
14 community signals

Julie Binoche

Julie is a renowned crypto journalist with a passion for uncovering the latest trends in blockchain and cryptocurrency. With over a decade of experience, she has become a trusted voice in the industry, providing insightful analysis and in-depth reporting on groundbreaking developments. Julie's work has been featured in leading publications, solidifying her reputation as a leading expert in the field.

Advertisement

Related Stories