Malicious Browser Extensions: How 16 Add-Ons Drained Crypto Wallets
Security·9 min read

Malicious Browser Extensions: How 16 Add-Ons Drained Crypto Wallets

Security researchers at Socket took apart 16 add-ons for Google Chrome and Microsoft Edge that quietly drained crypto wallets and harvested credentials. The uncomfortable part of the story: almost all of them entered the stores clean and picked up their payload later, through the kind of silent update nobody reads.

Here is how the scheme works, which signs give malicious browser extensions away, and what to do today if you keep crypto in a browser wallet.

What the researchers actually found

Socket described a cluster of 16 add-ons operating across two catalogs at once - the Chrome Web Store and the Microsoft Edge marketplace. Several had lived on those shelves for years with normal ratings, real reviews and an active audience.

The clearest example is Enable Right Click & Copy - Smart Unlock + OCR, a tool that removed copy restrictions. By the time it turned hostile it had more than 70,000 users in Chrome and around 10,000 in Edge. An add-on installed for a genuinely useful function became a weapon overnight without changing a pixel of its interface.

Researchers trace the activity back to at least 2024. Five of the sixteen were simply bought from their original authors - along with the audience, the reputation and the right to ship updates.

How a clean tool turns hostile

The scheme leans on two things: trust in the store, and the fact that updates install silently in the background.

  1. Acquisition or takeover. Attackers buy the add-on from its author or gain access to the developer account.
  2. A quiet release. The next version carries a loader - harmless on its own, with no obvious payload inside.
  3. Remote delivery. The loader pulls malicious code from a server after installation, so store review finds nothing.
  4. Extensibility. Modules are built to be topped up on demand: ad injection today, seed phrase theft tomorrow.

This is exactly why malicious browser extensions are so hard to catch. At publication there is nothing to detect, and the decision about who receives which payload is made on the attacker's server.

What the code does once installed

Technically the chain looks like this. The add-on opens an encrypted WebSocket connection to a command server, receives JavaScript modules and injects them into pages through hidden HTML elements. Along the way it strips Content Security Policy headers from every site you open - disabling the page's own defense against third-party scripts.

From that moment the browser stops being a neutral window. Everything you see and type is available to foreign code, and the activity runs in the background where nobody looks.

Wallets and exchanges in the line of fire

The crypto side of the attack is the painful one. The modules can:

  • drain wallets on EVM, Solana and Tron networks by swapping the "Connect Wallet" and "Swap" buttons;
  • serve phishing copies of Ledger and Trezor websites to capture seed phrases;
  • steal account credentials and assets on Coinbase, Binance, Kraken, OKX, MEXC, KuCoin and Bybit, as well as inside MetaMask.

Pay attention to the interface swap. A person clicks a familiar button on a familiar site, and the signature authorizes a transfer to the attacker. A hardware device helps only partly here - it protects the key, not your judgment, and it will faithfully sign whatever you approve on screen.

What else gets stolen

The same modules collect passwords typed on any site, pull data from Facebook and LinkedIn accounts, and export browsing history. In other words, this is full control over confidential data, not just over a wallet.

A separate trick is the fake browser update popup: the victim is talked into running a command that installs a full-featured stealer on the device.

The advertising branch: less scary, far more common

Not every hostile add-on hunts for crypto. Far more often you meet adware that monetizes your traffic instead.

Adware replaces the default search engine, rewrites results around a chosen keyword set, and redirects clicks to affiliate links. It also changes the start page, adds its own blocks among search results, and injects banners on sites that never carried ads.

The difference between the two branches is only in the goal. The mechanics are identical: an add-on with broad permissions, code delivered remotely, and users who notice nothing for months. Treat adware as reconnaissance - the same channel can deliver a seed phrase stealer next week.

Why the stores let this through

Store review is largely static: reviewers look at the code the developer uploaded. Malicious browser extensions clear that bar easily, because at review time the package is clean and the payload arrives a week after publication.

The second factor is volume. Thousands of products ship every day, and hostile ones stay lost in the flood until complaints pile up. Weeks pass between infection and removal, sometimes months, and the whole time the threat runs against a live audience.

The third factor is ownership transfer. Formally it breaks no rule - an author may sell their project. The catalog does not notify users about the deal, so a hostile version arrives under the old name with the old rating.

Signs worth noticing

Malicious browser extensions rarely announce themselves, but completely invisible attacks are rare too. What should put you on alert:

  • sluggish browser performance and unexplained load on the device;
  • a start page or search engine you did not choose;
  • ads on sites that never had them, and clicks routed through affiliate links;
  • an add-on you do not remember installing;
  • new permission requests on a tool that has worked for years.

A category of its own: add-ons that ask for access to all data on all websites. Sometimes that is justified, but for a translator or an ad blocker such rights are excessive.

How to audit what you have installed

Do this today rather than someday. Auditing your list is the only reliable way to find malicious browser extensions already sitting in your profile, and the procedure is the same in both browsers.

Chrome. Open chrome://extensions, enable developer mode and review the full list. For each item check the permissions, the last update date and whether the listing still exists in the store - a card that disappeared is a signal, not a coincidence.

Edge. Open edge://extensions and repeat. Edge users should be especially careful: when the report went public, part of the set was still available in that catalog.

A checklist per add-on:

  1. Who the developers are and whether they have a site with a real history.
  2. How many permissions are requested and whether they match the stated job.
  3. When the last release shipped and whether ownership changed hands.
  4. Whether recent reviews complain about hijacked search results.

How to pick safer tools

Reliability is not measured in stars. Three things matter: who develops the product, what rights it asks for, and how long it has lived under the same owner.

Free tools carry more risk - they are easier to buy and resell together with an audience. That does not make every free option dangerous; it means the bar for scrutiny is higher. For crypto work the safest arrangement is to run without browser add-ons at all and do swaps and rate comparison on a site where nothing needs installing.

A practical rule: the broader the permissions, the stronger the reputation must be. A tool that reads and changes data on every site should belong to a team with a public track record - otherwise it becomes dangerous the day it changes hands.

Reducing the risk

You cannot rule out malicious browser extensions entirely, but the cost of attacking you rises with a few simple habits.

  • Keep the bulk of your funds outside the browser. A hot wallet is for working balances; long-term holdings belong on a hardware device or on an exchange with withdrawal confirmations, where fees are visible before you commit.
  • Separate profiles. A dedicated browser profile with zero add-ons, used only for crypto, is the cheapest protection available.
  • Do not install a tool for a single function. Most converters, downloaders and unlockers are replaceable by built-in features or a web service.
  • Read the installer prompt. Permission to read and change data on all sites means full control over your sessions.
  • Verify the address before signing. Legitimate services never ask for a seed phrase.

What to do if an infected add-on was installed

Few steps, but order matters.

  1. Remove the suspicious add-on and restart the browser.
  2. Change passwords, starting with email and exchanges rather than minor services.
  3. Turn on two-factor authentication wherever it was missing.
  4. Move funds to a new wallet if there is any chance the seed phrase was entered on a fake page.
  5. Scan the device: fake update popups often leave a separate piece of malware behind.

A seed phrase that reached an attacker is compromised permanently. There is no rotation and no recovery - the money has to move to new addresses.

The short version

Cases like this share one trait: the victims did nothing obviously reckless. They did not download cracked files or click spam links. They used tools installed long ago that quietly changed owners. Auditing your list and keeping one clean profile for crypto closes most of that exposure in ten minutes.

FAQ
Can I trust an extension with a million installs?

Install count measures popularity, not safety. The add-on in this story had tens of thousands of users and a high rating - and all of it transferred to the attackers along with the codebase.

Does a hardware wallet protect me here?

It protects the private key but not your confirmation. If the screen shows a substituted address, the device will sign the transfer honestly.

Is antivirus enough against malicious browser extensions?

No. The payload lives inside the browser and arrives from a server after installation, so classic file scanning often misses it.

How do I know an extension changed hands?

There is no notification. Indirect signs are a sudden change in listing style, new permissions on update, and a spike of complaints in recent reviews.

About the author
Crypto Markets Expert & Head of Content and Marketing

Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading — turning on-chain data and market shifts into clear, actionable research for traders.

Share this articleTelegramX