← Blog · · df00tech

18 Chrome Extensions and 1 Edge Extension Caught Stealing Crypto Wallet Data

security-news campaign

Security researchers at Socket have identified a cluster of 19 browser extensions — 18 for Google Chrome and one for Microsoft Edge — that were published over the past six months and contain code designed to steal cryptocurrency wallet secrets and drain funds. Researcher Karlo Zanki reported that the extensions share overlapping code and tradecraft, suggesting a coordinated campaign that may have been active for an extended period.

Why It Matters

Browser extensions operate with broad access to page content and, in many cases, to wallet browser extensions and clipboard data — making them an effective vector for silently exfiltrating seed phrases, private keys, or session data tied to crypto wallets. Because these extensions were distributed through official extension stores, users who installed them had little reason for suspicion. Anyone who has installed lesser-known Chrome or Edge extensions related to crypto, wallets, or adjacent utility categories in the last six months should consider themselves potentially at risk.

What Defenders Should Watch For

  • Inventory browser extensions installed across the organization, particularly on endpoints used by finance, treasury, or engineering staff who may interact with crypto wallets.
  • Review extension permissions for overly broad access (e.g., <all_urls>, clipboard access, or access to wallet extension storage) and flag anything unnecessary for the extension's stated function.
  • Hunt for network connections from browser processes to unfamiliar or newly registered domains, which is a common exfiltration pattern for this type of malware.
  • Encourage users to remove unused or unverified extensions and to source extensions only from well-established, actively maintained publishers.
  • Monitor for unexpected wallet transactions or authorization requests following any suspected extension compromise.

This is a developing story based on a single vendor's research, and full details — including specific extension names, IOCs, and the scope of victim impact — may evolve as more information is published. For the original report, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.