A large-scale cryptocurrency theft campaign via seemingly harmless browser extensions has hit users worldwide, including Russia. My analysis shows that attackers have found an extremely sophisticated way to bypass app store protections, turning legitimate software into a tool for draining wallets.
Cybersecurity experts have discovered 18 malicious extensions for Google Chrome and one for Microsoft Edge that secretly siphon funds and steal credentials. The combined audience of two versions of one of the most dangerous add-ons reached 80,000 people. This is not just a theoretical threat—Russian users, who actively use such software for everyday tasks, have also been affected.
How the infection scheme works
The attack mechanics are striking in their sophistication. The extensions load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. Malicious code does not appear in the extension immediately—the first traces of attacker activity date back to 2024, indicating lengthy and careful preparation.
The most alarming aspect is the distribution method. Five of the sixteen extensions were purchased from original developers and infected via automatic updates. This means users who installed a seemingly safe add-on received malicious code only later, once trust in the program had already been established. A striking example is the extension Enable Right Click & Copy — Smart Unlock + OCR, whose user base exceeded 70,000 in Chrome and about 10,000 in Edge.
Technical details of the attack
After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. The malicious code can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Of particular danger is the spoofing of Ledger and Trezor hardware wallet pages to extract seed phrases.
The malicious code steals assets and account data from major exchanges—Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit—as well as from the MetaMask wallet. In essence, virtually all popular methods of storing and exchanging cryptocurrency are at risk.
A separate feature involves fake browser update notifications that push the victim toward actions needed by the attackers. All of this operates invisibly to the user, which explains why the danger went unrecognized for so long.
Additional threats and recommendations
Beyond browser extensions, experts are also recording a rise in phishing schemes involving fake AML checks and vulnerabilities in macOS. To anyone who suspects they may be infected, I strongly recommend treating their data as compromised, immediately changing passwords, and moving assets to new addresses. Those who stored cryptocurrency in affected wallets should ideally abandon old addresses entirely.
My expert conclusion: This attack is a stark reminder that even trusted extensions can become a Trojan horse. The crypto industry is moving toward greater security, but user vigilance remains the primary shield. Regularly reviewing the list of installed extensions and being skeptical of requests for broad permissions is not paranoia—it is necessary hygiene in the world of digital assets.