18 Chrome and 1 Edge Extension Caught Stealing Crypto Wallets
Cybersecurity researchers have uncovered a cluster of 19 browser extensions — 18 for Google Chrome and one for Microsoft Edge — that were secretly built to steal cryptocurrency wallet credentials and drain digital funds from victims. According to Socket security researcher Karlo Zanki, the extensions were published over the past six months and share strong similarities in their code and techniques, suggesting they are part of a coordinated campaign rather than isolated incidents.
Browser extensions often request broad permissions to access web pages, making them an attractive target for attackers looking to intercept sensitive information such as crypto wallet keys or seed phrases. Because these extensions can appear legitimate and pass through official web stores, users may install them without realising the risk, especially if they mimic popular wallet or productivity tools.
For small businesses that handle cryptocurrency or use browser extensions for daily operations, this discovery is a reminder that not everything in official extension marketplaces is safe. Staff should be encouraged to only install extensions that are strictly necessary, verify publisher reputation, and regularly audit installed browser add-ons across company devices.