Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Malicious Chrome and Edge Extensions Expose Growing Threat to Crypto Wallets and User Accounts

Malicious Chrome and Edge Extensions Expose Growing Threat to Crypto Wallets and User Accounts

By:
Last updated:August 31, 2026
Human Written
  • Security group named Socket found 19 bad browser add-ons targeting crypto wallets, online accounts and personal data.

  • Five trusted add-ons were bought from their creators and later turned bad through updates.

  • The malware can steal wallet secrets, login data and browser history while showing fake browser updates.

Socket Finds 19 Malicious Browser Extensions Targeting Crypto Wallets and Accounts

Hackers use browser add-ons disguised as useful tools to steal crypto, account data and private browser data.

Security group Socket found 19 add-ons tied to the operation. Eighteen work with Google Chrome, while one targets Microsoft Edge. The add-ons carry a flexible malware system that can fetch new features from hacker-run servers.

Socket said the operation may date back to February 2024. The group linked it to earlier DomainTools and Secure Annex work.

Attackers Turn Trusted Add-ons Into Malware

Socket found that 14 of the 19 add-ons came from the attacker. The other five had a different path. The attackers bought those five add-ons from their creators. They later pushed updates that added bad code. This method gives attackers access to a user base. It also lets them hide behind trust built before the takeover.

A separate crypto-stealing campaign uses a similar strategy to bypass browser security. The Silent Swap malware deploys a fake “Google Notes” extension to Chromium-based browsers by modifying protected browser preference files and recalculating integrity verification values to make the malicious extension appear as though it was legitimately installed.

The biggest possible user reach involved Enable Right Click & Copy Smart Unlock + OCR. Socket said the Chrome version had about 70,000 users when the bad code appeared.

Its Edge version had about 10,000 users. That gives the two versions a possible reach of about 80,000 users. It does not mean all those users installed a bad version.

Chrome had removed the add-on from its Web Store when Socket published its findings. The Edge version remained available at that time, according to Socket.

The Malware Can Steal Crypto and Login Data

The malicious add-ons use a central system that can download separate malware code after installation. Socket observed 16 malicious modules. They cover crypto theft, account theft, social media theft and browser history theft. The researchers said the list may not be complete because the malware can load new tools over time.

One module targets crypto wallets on Ethereum networks, Solana and Tron. It can alter wallet buttons on websites and redirect users into hacker-run payment steps.

Another module targets hardware wallet owners. It can replace real Ledger and Trezor pages with fake pages that ask for wallet seed words. That creates a real risk. Anyone who gives away a recovery phrase can lose control of the wallet tied to it.

The malware also targets major crypto services. Socket found tools aimed at OKX, MEXC, Kraken, Binance, KuCoin, Coinbase, Bybit and MetaMask. These tools can collect account data, balances, cookies and login data. Attackers can use stolen session data to access accounts without asking for the victim’s password again.

A password grabber also records data typed into text, email, and password boxes. Other tools target Facebook and LinkedIn accounts.

Fake Browser Updates Add Another Threat

The operation also uses ClickFix, a trick that uses fake error and update messages. This malware can place a fake browser update message on a website. It tells the user that the browser needs an urgent update.

The page then tries to trick the victim into copying and running a hacker command. The victim may think this will fix the browser. It can instead run bad code. Socket said the fake update tool can serve different content based on the victim’s browser and system. That can help the scam look more real.

The Add-ons Weaken Browser Safety

The malware also tampers with Content Security Policy, or CSP, on websites. CSP helps sites control which scripts can run. Socket found that the bad add-ons remove CSP headers from sites they visit.

The malware can then inject its own JavaScript into those pages. This lets attackers control what users see and what data the browser sends.

The add-ons also maintain WebSocket links to control servers. These links let the malware get orders and new tools. This setup gives the attackers room to change the malware without releasing a new add-on.

What Users Should Do

Socket said the list of tools seen so far may not be the last. The attackers can add new features as the attack grows.

The case shows a key risk with browser add-ons. A tool can start as trusted and turn bad after an owner changes or updates.

Chrome normally updates add-ons on its own. That feature helps users get fixes, but it can also spread a bad update to many users.

Users are advised to verify the installed add-ons and delete those that they do not require. Also, users should verify if any of their installed add-ons is part of the 19 affected add-ons Socket mentioned.

Anyone who used a bad add-on should treat saved logins and active sessions as exposed. Change passwords first, especially for important accounts.

Crypto users face a bigger risk if they entered a recovery phrase or used a wallet while the malware ran. Socket recommends moving funds to a newly created wallet when an infected add-on may have leaked wallet secrets. Socket has published the add-on IDs and network data linked to the operation.

This campaign makes it clear a small browser add-on can turn into a real problem. The best move? Keep your add-ons to a minimum. Review them regularly. And get rid of the ones you don’t use anymore.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.