A large-scale digital asset theft campaign has affected users of popular browsers. In the course of my in-depth analysis of the browser extension ecosystem, 18 malicious extensions for Google Chrome and one for Microsoft Edge were discovered. These seemingly harmless utilities not only drain cryptocurrency wallets but also steal credentials, passwords, and browsing history.
The combined audience of the infected extensions is impressive—around 80,000 users, with a significant portion located in Russia. The threat is global in nature, and Russian crypto asset holders are at risk on par with users from other countries.
Infection Mechanics and Attack Vector
What is particularly alarming is the attackers' tactics. Five of the sixteen extensions studied were purchased from their original developers, after which malicious code was injected into them via automatic updates. This is a classic supply chain attack, where the victim trusts a familiar tool without suspecting it has been compromised.
For example, the extension "Enable Right Click & Copy — Smart Unlock + OCR," which works in Chrome and Edge, already had a base of more than 70,000 users in Chrome and about 10,000 in Edge by the time it was discovered. After installation, the program establishes an encrypted WebSocket connection with a command-and-control (C2) server and downloads JavaScript modules. The malicious code strips Content Security Policy (CSP) headers from visited websites and injects hidden HTML elements to intercept data on cryptocurrency exchanges.
The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Moreover, phishing pages mimicking Ledger and Trezor interfaces are created to extract seed phrases. Accounts on Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask have been affected.
How to Protect Yourself
All discovered extensions have already been removed from the Chrome Web Store; however, the Edge version, according to available data, may have remained available in the Microsoft Store. I strongly recommend that anyone who installed such add-ons consider their data compromised and immediately change their passwords. If you stored cryptocurrency in affected wallets—transfer your assets to new addresses.
This is not the only threat. Specialists are also recording an increase in phishing services that mimic AML address checks and the exploitation of vulnerabilities in macOS. Regularly auditing installed extensions and being wary of requests for expanded permissions are critically important precautionary measures.
My comment: This attack is a vivid example of how cybercriminals monetize user trust in legitimate tools. Given the growing complexity of threats, simply installing extensions from official stores no longer guarantees safety. The key principle is minimization: install only what is truly necessary and regularly review permissions. Security in cryptocurrency begins with the hygiene of your browser.