{"id":8448,"date":"2025-11-14T10:03:42","date_gmt":"2025-11-14T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/14\/malicious-chrome-extension-as-ethereum-wallet-enables-full-wallet-takeover\/"},"modified":"2025-11-14T10:03:42","modified_gmt":"2025-11-14T10:03:42","slug":"malicious-chrome-extension-as-ethereum-wallet-enables-full-wallet-takeover","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/14\/malicious-chrome-extension-as-ethereum-wallet-enables-full-wallet-takeover\/","title":{"rendered":"Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover"},"content":{"rendered":"<p>    Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A deceptive Chrome extension named Safery: Ethereum Wallet has emerged as a serious threat to cryptocurrency users.<\/p>\n<p>Published on the Chrome Web Store on November 12, 2024, this extension masquerades as a secure Ethereum wallet while secretly stealing user seed phrases.<\/p>\n<p>The malware\u2019s sophisticated design allows attackers to gain complete control over victims\u2019 cryptocurrency wallets and drain their digital assets.<\/p>\n<p>The extension operates with a cunning approach to theft. When users create or import a wallet, the extension extracts their seed phrase and encodes it into synthetic Sui <a href=\"https:\/\/cybersecuritynews.com\/blockchain-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain<\/a> addresses.<\/p>\n<p>It then broadcasts tiny microtransactions of 0.000001 SUI to these encoded addresses from a threat actor-controlled wallet. To observers, these appear as normal blockchain activity, but they actually contain hidden user data.<\/p>\n<p>Socket.dev security analysts <a href=\"https:\/\/socket.dev\/blog\/malicious-chrome-extension-exfiltrates-seed-phrases\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malicious extension and discovered its evasive tactics.<\/p>\n<p>The researchers noted that the backdoor uses BIP-39 mnemonic encoding, transforming each seed phrase word into numeric indices and packing them into hexadecimal strings that resemble legitimate Sui wallet addresses.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh8sIszV7JpPUD1hmrSR1HFOO5m0cZc0tubLH1tU4fl-Gdn_EawBV8BoDutIPXGLKnQvlExJQcQGJQDbiuqxHGCULj9juVoEbXr3NGVi942fywGQHeyPAsu20LJjm7f-_hX9ojYqQFY6kLRy_A_N0kKKX7b2InkjDnvPjqlba8nQcHk5jso6KdsowHRzcM\/s16000\/Ethereum%2520Wallet%2520markets%2520the%2520extension%2520as%2520a%2520simple%2C%2520secure%2520ETH%2520wallet%2520%28Source%2520-%2520Socket.dev%29.webp?ssl=1\" alt=\"Ethereum Wallet markets the extension as a simple, secure ETH wallet (Source - Socket.dev)\"><figcaption class=\"wp-element-caption\">Ethereum Wallet markets the extension as a simple, secure ETH wallet (Source \u2013 Socket.dev)<\/figcaption><\/figure>\n<\/div>\n<p>This clever approach hides data within blockchain transactions, eliminating the need for traditional command-and-control servers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-mechanism\"><strong>Technical Mechanism<\/strong><\/h2>\n<p>The technical mechanism reveals the extension\u2019s sophistication. When examining the extension code, analysts found it loads a standard wordlist, maps each word to its index, and constructs synthetic addresses prefixed with \u201c0x\u201d.<\/p>\n<p>A paired decoder embedded in the malware allows the threat actor to reverse this process, reconstructing the original seed phrase word by word.<\/p>\n<p>The code silently executes these operations after a user enters their seed phrase, sending <a href=\"https:\/\/cybersecuritynews.com\/data-exfiltration-prevention\/\" target=\"_blank\" rel=\"noreferrer noopener\">exfiltration data<\/a> across the blockchain before completing the login process.<\/p>\n<p>The threat proves especially dangerous because the extension appears legitimate on the Chrome Web Store. Users searching for <a href=\"https:\/\/cybersecuritynews.com\/malicious-npm-packages-attacking-ethereum-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ethereum wallets<\/a> find it listed as the fourth result alongside trusted alternatives like MetaMask and Enkrypt, lending it false credibility.<\/p>\n<p>Once a victim installs the extension and imports their wallet, the attacker gains access to all derived Ethereum private keys and can transfer all assets to their own addresses, resulting in complete financial compromise.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/malicious-chrome-extension-as-ethereum-wallet\/\">Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/malicious-chrome-extension-as-ethereum-wallet\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover A deceptive Chrome extension named Safery: Ethereum Wallet has emerged as a serious threat to cryptocurrency users. Published on the Chrome Web Store on November 12, 2024, this extension masquerades as a secure Ethereum wallet while secretly stealing user seed phrases. The malware\u2019s sophisticated design [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8448","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8448"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8448"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8448\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}