A set of malicious browser extensions was caught using Chrome and Edge as a backdoor into crypto wallets, exchange accounts, and social logins.
- Socket identified 19 malicious extensions
- 18 were tied to Chrome, one to Edge
- Some were fake from the start; others were reportedly legitimate extensions later weaponized
- The campaign targeted wallets, exchanges, and social accounts
- One extension had about 70, 000 Chrome users and 10, 000 Edge users
Cybersecurity researchers at Socket say they uncovered a campaign built around malicious browser extensions designed to steal crypto wallets and sensitive data. Their findings point to activity across Google Chrome and Microsoft Edge, with signs the operation may date back to February 2024.
The trick is ugly, but it works. A browser extension sits between you and the webpage. If that extension can read, alter, or redirect what happens on a site, it can mess with wallet connections, spoof prompts, and push victims into handing over access they never meant to give. In crypto, that can mean irreversible loss in a few clicks. Self-custody is freedom, but it is also a trapdoor if you get lazy.
Socket says the campaign involved 19 crypto-stealing malicious browser extensions: 18 for Chrome and one for Edge. The firm also said the extensions were published or weaponized over the past six months. In some cases, attackers created extensions that looked legitimate at first. In others, they reportedly acquired existing extensions from original developers and later turned them malicious.
That split matters. A fresh fake extension is bad enough, but a previously trusted add-on that later changes hands is the nastier play. Users tend to trust things that have been around for a while, especially if the icon looks familiar and the reviews do not scream “obvious scam.” That trust can be a liability.
According to Socket, 14 of the 19 extensions were created by the threat actor, while five were purchased from legitimate authors.
The most dangerous extension was described as “Enable Right Click & Copy, Smart Unlock + OCR”. Socket said the Chrome version had about 70, 000 users when malicious functionality was introduced, while the Edge version had roughly 10, 000 users. The Chrome extension has since been removed from the Chrome Web Store; the Edge version was still active at the time Socket published its findings.
Those user counts are not a footnote. Even a smaller extension can cause real damage if it has the wrong permissions and the right criminal payload. Crypto theft does not need massive scale to be profitable. One compromised wallet can be enough to keep a fraud ring busy for a while.
Socket said the malware removes Content Security Policy, or CSP, protections from websites. CSP is a browser-supported defense that limits where a page can load scripts and other content from. Weakening it makes it easier for attackers to inject code, alter what users see, or slip fake interface elements into a page.
That technical detail matters because the extensions were not just stealing passwords in a dumb, clumsy way. Socket said the campaign tampered with common crypto-site controls like “Connect Wallet” and “Swap” buttons. Those are the exact spots where users approve wallet connections and token trades. If an extension can meddle there, it can redirect users toward malicious approval flows, fraudulent prompts, or wallet-draining scams that look annoyingly normal until the funds are gone.
The campaign also targeted hardware-wallet users with fake Ledger and Trezor recovery or update pages. That should kill the fantasy that hardware wallets make someone untouchable. They are excellent for protecting private keys, but they do not stop phishing, fake updates, or a user typing a seed phrase into a scam page. If a recovery phrase gets exposed, the hardware wallet is no longer the hero of the story.
Socket said the targeting list extended beyond wallets to major crypto services including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit and MetaMask. Additional modules went after Facebook and LinkedIn accounts, stole browsing history, and deployed ClickFix-style fake browser-update pages.
That wider spread is telling. This is not just a crypto theft operation in the narrow sense. It looks more like a credential-harvesting and session-theft setup that happens to love crypto targets most of all. Facebook and LinkedIn are useful to attackers too, whether for identity abuse, social engineering, or building trust with future victims. Criminals do not stop at the shiny stuff if there is more loot in the cupboard.
For readers unfamiliar with some of the terms: EVM-compatible refers to blockchains that work with Ethereum-style smart contracts and wallet tools. Solana and Tron use different systems, but the outcome is the same from the attacker’s point of view, steal access wherever assets are held, and let the user sort out the wreckage later. Related campaigns have shown the same ugly pattern in other corners of the web, including Chrome Extensions Caught Stealing Crypto Wallets, the Trojan malware targeting crypto wallets and banking apps, the ClickFix scam targeting macOS crypto wallets, and the Solana memo exploit tied to GlassWorm malware.
The broader lesson is simple: browser extensions are a serious attack surface. People install them for convenience and then hand over broad access without thinking much about it. That is fine for a calculator widget or a screenshot tool. It is reckless when the add-on can sit between you and a wallet connection.
Regularly reviewing installed extensions is not boring security theater. It is basic hygiene. Remove anything suspicious, anything you do not recognize, and anything you no longer use. Be wary of extensions that suddenly ask for new permissions, especially if they involve crypto sites or login pages. A helpful tool does not need to act like a creep.
Key questions and takeaways
-
Why are malicious browser extensions such a big crypto threat?
Because they can read and alter what happens on webpages, including wallet connections, swap flows, and login pages. That gives attackers a direct path to credentials, session tokens, and malicious transaction prompts. -
Does a hardware wallet stop this kind of attack?
Not by itself. Hardware wallets protect private keys, but they cannot stop phishing pages, fake update prompts, or a user being tricked into revealing a seed phrase. -
Why does Content Security Policy matter?
CSP helps a website block unwanted scripts and content. If a malicious extension removes that protection, it becomes easier to inject code and manipulate what the user sees. -
What should users do right now?
Review installed browser extensions, remove suspicious ones, and reinstall only from official sources when needed. Treat any extension update or wallet prompt that asks for extra access as a red flag.
The crypto industry loves talking about decentralization, but the uncomfortable truth is that a lot of users still hand their fate to centralized browsers, extension stores, and trust signals they barely check. That is where scams thrive. The chain is only as strong as the weakest link, and very often the weakest link is a browser add-on somebody forgot they installed six months ago.
Bitcoin and crypto were meant to reduce gatekeepers, not replace them with sketchy plugins and fake recovery pages. If an extension wants to sit between you and your funds, it needs to earn that trust every single day. Most of them do not.