XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

19 Malicious Browser Extensions Exposed in Massive Crypto Wallet Theft Campaign

Security researchers uncover a sophisticated operation using fake and compromised browser extensions to steal cryptocurrency wallets, session credentials, and personal data from millions of users.

JM
by Jacob Marquez · Learn Desk
Published August 28, 2026 · 3 min read

A Growing Threat to Crypto Users

According to Socket, a cybersecurity research firm, investigators have identified a coordinated campaign deploying 19 malicious browser extensions designed to drain cryptocurrency wallets and steal sensitive account information from exchanges and wallet providers. The operation, which appears to span at least six months and may have originated as far back as February 2024, employed two distinct tactics: creating entirely fraudulent extensions from scratch or acquiring legitimate extensions from their original developers before weaponizing them with malicious code.

Of the 19 extensions analyzed, Socket found that 14 were developed by the threat actors themselves, while five were purchased from legitimate authors. Eighteen of the malicious extensions targeted Google Chrome users, with an additional extension weaponized for Microsoft Edge. The campaign demonstrates a sophisticated understanding of browser extension distribution and the trust users place in their extensions.

The Most Dangerous Extension

Socket identified “Enable Right Click & Copy — Smart Unlock + OCR” as the most dangerous extension in the campaign. When Socket detected its malicious functionality, the Chrome version had accumulated approximately 70,000 users, while its Edge variant reached about 10,000 installations. Google has since removed the Chrome version from the Chrome Web Store, but the Edge version remained active at the time of Socket’s report. The malware operates by removing Content Security Policy protections from websites, giving attackers greater latitude to manipulate web pages and capture user interactions.

Multi-Chain Targeting and Attack Methods

The malicious extensions employ a multi-chain approach to cryptocurrency theft, targeting wallets compatible with Ethereum Virtual Machine networks, Solana, and Tron blockchains. Socket’s researchers discovered that the malware actively tampers with legitimate “Connect Wallet” and “Swap” buttons, redirecting users to attacker-controlled transaction flows that drain their holdings.

For hardware wallet users, the operation deployed convincing fake recovery and update pages mimicking Ledger and Trezor interfaces, attempting to trick victims into revealing their seed phrases. Beyond direct wallet theft, the campaign harvests authenticated sessions and account credentials from major cryptocurrency platforms including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, and Bybit, as well as the MetaMask wallet extension. The extensions also target personal accounts on Facebook and LinkedIn, steal browsing history, and deploy fake browser-update pages in the ClickFix style.

Protecting Yourself

Socket recommends that users regularly audit their installed browser extensions and remove any suspicious additions. This incident underscores the importance of obtaining extensions only from official stores and verifying developer credentials before installation.

Security breaches targeting cryptocurrency infrastructure directly impact market confidence and user adoption across all blockchain networks.

Source: Socket, via U.Today. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.