My analysis of the situation shows that we are dealing with one of the most organized and technically advanced campaigns to steal crypto assets in recent times. Through in-depth research, I managed to identify 18 malicious extensions for Google Chrome and one for Microsoft Edge, which collectively attacked tens of thousands of users worldwide, including a significant number of Russians.
The combined audience of the infected add-ons reached an impressive 80,000 people. The most telling example is the extension Enable Right Click & Copy — Smart Unlock + OCR, which operated in both browsers. Its base in Chrome exceeded 70,000 users, and in Edge — about 10,000. These are not just random one-off programs, but a carefully planned multi-step operation, traces of which lead back to 2024.
Attack mechanics: how funds are stolen
The attackers act cold-bloodedly and deliberately. Five of the sixteen extensions were purchased from their original developers, after which malicious code was injected into them through automatic updates. This approach allowed them to remain unnoticed for a long time: at the time of publication in the Chrome Web Store, the add-ons looked completely legitimate.
After installation, the program establishes an encrypted WebSocket connection with a command-and-control server (C2) and downloads JavaScript modules. These modules can not only intercept passwords and browsing history, but also directly drain EVM, Solana, and Tron wallets. By forging the "Connect Wallet" and "Swap" buttons, hackers gain access to funds on the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — and in MetaMask. Particularly dangerous is the spoofing of Ledger and Trezor hardware wallet pages to extract seed phrases.
Why this affects everyone
It is important to understand: the threat is not limited to one country. The extensions strip Content Security Policy (CSP) protection headers from visited sites and inject hidden HTML elements to steal data. Externally, the add-on continues to perform its stated functions, so the user may not notice anything suspicious until they discover an empty wallet.
All found extensions have already been removed from the Chrome Web Store, however, the Edge version, according to the data I have, may still be available in the Microsoft Store. For those who installed suspicious add-ons, I strongly recommend treating their data as compromised, immediately changing passwords, and transferring assets to new addresses.
Experts also note a rise in related threats: phishing services that "check" addresses for involvement in money laundering (AML) and the use of vulnerabilities in macOS for unauthorized access to victims' computers.
My verdict: this campaign is a vivid example that even "harmless" browser extensions can become a Trojan horse. Regularly review the list of installed add-ons, pay attention to requested permissions, and never store large sums in "hot" wallets connected to the browser. Security in cryptocurrency is above all about hygiene and constant vigilance.