Crypto Exchanges

Story: 80,000 Crypto Users Targeted by 19 Malicious Browser Extensions in Chrome and Edge

By Julie Binoche

1 / 15

How the Wallet Drainer Actually Works. The technical setup is pretty sophisticated. Socket's researchers found a multi-chain…

2 / 15

Social Media Accounts Also in the Crosshairs. Crypto isn't the only target. The campaign also goes after Facebook and LinkedIn accounts.

3 / 15

What Socket Says Users Should Do. Socket's advice is direct: regularly audit your browser extensions.

4 / 15

Crypto wallets are getting drained. Quietly, methodically, and at scale — through something most users never think twice about: browser extensions.

5 / 15

Cybersecurity firm Socket uncovered a campaign built around 19 malicious browser extensions, 18 targeting Google Chrome and one targeting Microsoft Edge.

6 / 15

The biggest single extension in the bunch had about 70,000 users.

7 / 15

That's "Enable Right Click & Copy — Smart Unlock + OCR," which Socket flagged as the most dangerous extension in the campaign. Chrome pulled it from the Web Store.

8 / 15

The technical setup is pretty sophisticated. Socket's researchers found a multi-chain cryptocurrency wallet drainer embedded in the extensions.

9 / 15

Hardware wallet users aren't safe either. The campaign includes fake recovery and update pages designed to look like official Ledger and Trezor interfaces.

10 / 15

And the reach goes wider than just DeFi buttons and hardware wallet tricks. The extensions include modules built to harvest authenticated session data and account credentials…

11 / 15

Read also: The Sandbox Commits to 1:1 SAND Repayment After $700K Bridge Exploit

12 / 15

One of the more technically alarming pieces is what Socket said about Content Security Policy protections.

13 / 15

Crypto isn't the only target. The campaign also goes after Facebook and LinkedIn accounts. Modules designed to compromise those accounts are baked into the same extensions.

14 / 15

There's also a ClickFix-style component. Fake browser-update pages that mimic legitimate Chrome or Edge update prompts push users to download additional malware.

15 / 15

Browsing history is also being harvested. That data can be used to build profiles, identify which crypto platforms a user frequents, and tailor further attacks accordingly.

The Currency Analytics

Want the full story?