Press Enter to search · ESC to close

Crypto

19 Malicious Chrome/Edge Extensions Found Draining Crypto Wallets via C2 Servers

Socket discovered 19 malicious Chrome and Edge extensions that use C2 servers to steal crypto wallet keys and credentials. The incident highlights the growing supply-chain risk in browser extensions and the need for stronger client-side security in crypto.

News Summary

Security research firm Socket has identified 19 malicious browser extensions—18 for Chrome and 1 for Edge—that can remotely deploy malicious modules via command-and-control (C2) servers to steal crypto wallet private keys, seed phrases, exchange credentials, and other sensitive account data. The extensions were reportedly distributed through official web stores, posing a significant supply-chain risk for crypto users.

Industry Analysis

This discovery underscores a growing attack vector in the crypto ecosystem: the browser extension supply chain. While users often focus on phishing sites or malicious smart contracts, extensions represent a trusted layer that can access browsing activity, clipboard contents, and even directly interact with web-based wallets like MetaMask or exchange dashboards.

The use of a remote C2 infrastructure is particularly concerning. It allows attackers to update malicious functionality dynamically, bypassing static detection and making the extensions adaptable to new targets or evasion techniques. This modular approach means that even if an extension initially appears benign, it can later receive instructions to exfiltrate credentials or sign malicious transactions.

For crypto users, the implications are severe. Browser extensions are often granted broad permissions—reading and changing data on all websites, accessing browsing history, and in some cases, injecting scripts. A compromised extension can effectively hijack a user’s active sessions, steal private keys stored in browser-based wallets, or capture password manager entries. The fact that these were available on official stores adds a layer of deception, as users typically trust these platforms to have basic security screening.

This incident also highlights a broader trend: as on-chain security improves, attackers are pivoting to the periphery—browser extensions, third-party APIs, and hardware wallet bridge software. The crypto industry has invested heavily in smart contract audits and formal verification, but client-side security remains a weak link.

Forward-Looking Perspective

Going forward, we can expect increased scrutiny on browser extension security, particularly those related to crypto. Regulatory bodies may begin to hold extension developers accountable for inadequate security practices. Meanwhile, wallet providers might implement additional safeguards, such as requiring hardware wallet confirmation for all transactions, or using iframe isolation to prevent extension interference.

Users should adopt a defense-in-depth approach: regularly audit installed extensions, remove unused ones, use dedicated browsers for crypto activities, and consider using hardware wallets with physical confirmation. Additionally, monitoring tools like Socket’s extension scanner could become standard practice for security-conscious users.

The discovery also opens a conversation about the need for more robust vetting processes in Chrome and Edge web stores. While Google and Microsoft have automated scanning, the sophistication of these malicious extensions suggests that manual review or community reporting mechanisms may need enhancement.

Ultimately, this is a reminder that in crypto, self-custody extends beyond private keys—it includes the entire digital environment in which those keys are used. As the ecosystem matures, expect security to become a more prominent factor in user adoption and trust.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback