Hackers steal crypto through malicious Chrome and Edge extensions
EUR/MDL - 20.16 0.1229
USD/MDL - 17.28 0.4119
VMS_91 - 3.03%
VMS_364 - 9.54%
BONDS_2Y - 7.40%
GOLD - 4,455.55 0.01%
EURUSD - 1.16 0%
BRENT - 83.76 1.92%
SP500 - 769.35 0.23%
SILVER - 66.37 0%
GAS - 2.89 8.25%

Hackers are stealing cryptocurrency through Chrome and Edge browser extensions

Socket experts found that initially, when they first appeared in the Chrome Web Store, many of these extensions did not contain malicious code. Five of the 16 were purchased from their original developers and infected with malware through automatically distributed updates. This means that the modules identified are extensible—attackers can add malicious code as needed. The authors of the browser security study believe that hackers began doing this in 2024.
Igor Fomin Reading time: 2 minutes
Text size
Link copied
Bitcoin hackers

One such extension, “Enable Right Click & Copy — Smart Unlock + OCR”, is available for Chrome and Edge. When the program became malicious, its user base in Chrome numbered more than 70,000 people, and in Edge—about 10,000, according to estimates by Socket, as reported by bits.media.

Once it appears in the browser, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every visited site, and injects malicious scripts via hidden HTML elements. This allows hackers to intercept user data on crypto exchange websites and other services.

Socket researchers discovered that the malicious modules can drain EVM wallets, Solana, and Tron by spoofing the “Connect Wallet” and “Exchange” buttons, as well as replacing the websites of Ledger and Trezor hardware wallets with phishing pages to steal seed phrases. The malicious modules also steal crypto assets and account data from major crypto exchanges—including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, and Bybit—as well as from the MetaMask crypto wallet.

In addition, the extensions transmit to hackers the data and passwords entered on all websites, collect information from Facebook and LinkedIn accounts, and extract browsing history. The malware also displays fake browser updates, prompting victims to carry out commands desired by the attackers. None of the malicious extensions are currently available in the Chrome Web Store, but Edge users are advised to check their installed extensions.

Malwarebytes Labs recently warned of a new phishing scheme—hackers are creating fake websites that purport to verify crypto addresses for money laundering and violations of international sanctions (AML). To gain unauthorized access to computers, hackers also exploited a vulnerability in the “Screen Sharing” feature of Apple’s macOS operating system.


Follow our updates


Реклама недоступна
Related*
More from author*
Moldova’s Economy
31 August 2026
Politics & Economy
31 August 2026
Moldova’s Economy
31 August 2026
Economy & Law
30 August 2026

We always appreciate your feedback!

Latest news
Popular now*
Must Read*