Fake Crypto Wallet Ranks Fourth on Chrome Web Store While Stealing User Funds

Fake Crypto Wallet Ranks Fourth on Chrome Web Store While Stealing User Funds
фото показано с : bravenewcoin.com

2025-11-15 01:39

The malicious extension called “Safery: Ethereum Wallet” appears legitimate at first glance. It ranks just behind trusted wallets like MetaMask when users search for “Ethereum Wallet” on the Chrome store. However, security researchers have discovered it contains hidden code designed to steal cryptocurrency from anyone who uses it.

How the Scam Works

The fake wallet uses a sophisticated method to steal user seed phrases. When someone creates a new wallet or imports an existing one, the extension secretly encodes their 12 or 24-word seed phrase into fake Sui blockchain addresses.

The malicious code then sends tiny transactions worth 0.000001 SUI tokens to these encoded addresses. To outside observers, these look like normal blockchain activity. But the attackers can decode these transactions to recover the victim’s complete seed phrase and gain full control of their crypto wallet.

Source: socket.dev

Socket’s security team discovered this extension and explained how it works. “The mnemonic leaves the browser concealed inside normal looking blockchain transactions,” their report states. This makes the theft nearly impossible to detect using traditional security methods.

Warning Signs Users Missed

Several red flags should have warned users away from this fake wallet. The extension has zero user reviews and contains grammatical errors in its description. It also lacks an official website and lists only a Gmail address for developer contact.

The extension was initially uploaded on September 29, 2025, with the most recent update on November 12, 2025. Despite these obvious warning signs, the fake wallet managed to climb to fourth place in search rankings, potentially exposing thousands of users to theft.

Security experts say this high ranking gives the malicious extension “immediate visibility and a veneer of legitimacy to unsuspecting users.” This positioning dramatically increases the chances that people will download and use the fake wallet before discovering its true nature.

Growing Threat to Crypto Users

Browser extension scams represent a growing problem in the cryptocurrency space. Industry data shows that wallet-related scams drained over $500 million in 2024 alone, with browser extensions becoming an increasingly popular attack vector according to industry reports.

The timing of this discovery is particularly concerning. AI-powered crypto tools are becoming more popular, with AI agent tokens growing 222% in late 2024. As more people seek convenient ways to manage their cryptocurrency, they become more vulnerable to fake tools that promise easy solutions.

This fake wallet represents a new level of sophistication in crypto theft. Unlike simple phishing websites that might be obvious scams, this extension appeared in Google’s official store alongside legitimate options. The blockchain-based method of stealing seed phrases is also innovative, using the transparency of blockchain networks against users.

Current Status and Response

As of November 14, 2025, the Safery extension remains available for download on the Chrome Web Store. Socket reported the malicious extension to Google’s security team and requested removal of the publisher account, but the extension has not yet been taken down.

The extension’s continued availability highlights ongoing problems with app store security reviews. While Google has policies in place to prevent malicious software, sophisticated scams like this one can slip through the approval process and remain available for weeks or months.

Security researchers warn that this technique could spread to other blockchain networks. The method works by exploiting the public nature of blockchain transactions, meaning similar attacks could target users of Solana, Ethereum, or other cryptocurrency networks.

How to Stay Safe

Users can protect themselves by following several key security practices. Always research any crypto wallet or extension before installation. Look for established tools with thousands of positive reviews and verified developers.

Legitimate crypto wallets like MetaMask undergo regular security audits by professional firms. They also maintain official websites with detailed documentation and support resources. Fake wallets typically lack these features.

Never share seed phrases with anyone, and be suspicious of any software that asks for your complete seed phrase during normal operation. Legitimate wallets only require seed phrases during initial setup or recovery processes.

Monitor your wallet transactions regularly for any unexpected activity. Even tiny transactions could indicate that your seed phrase has been compromised. Use blockchain explorers to review all incoming and outgoing transactions from your addresses.

Enable two-factor authentication on crypto exchanges and wallet services whenever possible. While this won’t protect against seed phrase theft, it adds an extra security layer for online accounts.

The Digital Wild West Continues

This incident shows that cryptocurrency remains a target-rich environment for scammers. Despite years of warnings about security risks, fake wallets and malicious extensions continue to fool users and steal millions of dollars.

The sophistication of this particular scam – using blockchain transactions to hide stolen data – suggests that attackers are constantly developing new methods to stay ahead of security measures. Users must remain vigilant and stick to well-established, audited tools when managing their cryptocurrency assets.

origin »

Bitcoin price in Telegram @btc_price_every_hour

Atomic Wallet Coin (AWC) на Currencies.ru

$ 0.0834325 (+0.40%)
Объем 24H $3.674k
Изменеия 24h: 4.07 %, 7d: 4.52 %
Cегодня L: $0.0743395 - H: $0.08424
Капитализация $884.69k Rank 1962
Цена в час новости $ 0.0840878 (-0.78%)

web store stealing fake chrome wallet crypto

web store → Результатов: 126


Фальшивый Ethereum-кошелек в Chrome Web Store крадет сид-фразы

Платформа безопасности блокчейна Socket предупредила о новой угрозе, которая маскируется под надежный кошелек. Расширение для Ethereum в Chrome Web Store занимает четвертое место в поиске и крадет сид-фразы пользователей через хитрую схему с микротранзакциями.

2025-11-14 10:27


SimpleHold Review – Is SimpleHold A Legit & Safe Crypto Wallet?

In this article, we will review what is Simplehold wallet is and why you should think about installing it as your go to web/mobile crypto wallet. What Is SimpleHold Security is of great importance when dealing with cryptocurrencies; that is why it is of ultimate importance to choose a secure and reliable wallet to store […] The post SimpleHold Review – Is SimpleHold A Legit & Safe Crypto Wallet? appeared first on CaptainAltcoin.

2022-4-5 18:22


Amazon предложил услуги по облачному майнингу криптовалюты Chia

Технологический гигант Amazon представил решение для майнинга криптовалюты Chia на своей платформе облачных вычислений Amazon Web Services (AWS). Об этом сообщает The Block. В кратком руководстве компания рассказывает об особенностях добычи Chia и предлагает несколько вариантов использования их облачной системы для этих целей: вычислительные ресурсы Amazon Elastic Compute Cloud, которые обладают большим объемом памяти и высокочастотным процессором;хранилище Amazon Elastic Block Store с жесткими дисками большой емкости с улучшенными возможностями чтения и записи;объектное хранилище большой емкости и недорогое пространство Amazon Simple Storage Service для хранения большого количества файлов.

2021-5-8 13:18


LEAD Wallet Launches Its Super Simple Application; Even Your Grandma Would Be Able to Use It

PRESS RELEASE. Lead Wallet, a new crypto wallet application, has officially been launched on Google Play Store, and it will also launch its iOS and web version soon. This crypto wallet application is different from other existing wallet apps because it aims to be a super simple crypto app that most people would find easy […] The post LEAD Wallet Launches Its Super Simple Application; Even Your Grandma Would Be Able to Use It appeared first on Bitcoin News.

2020-12-17 20:00


Фото:

Orchid: Bringing Decentralization to VPNs

Whenever we browse the web, read news online, or purchase a new pair of glasses from an e-commerce store, we leave traces. These traces sometimes show us content that actually provides us with value, but more often the information we leave is used in concerning ways with scandals like Cambridge Analytica just forming the tip […] The post Orchid: Bringing Decentralization to VPNs appeared first on Bitcoin News.

2020-8-5 17:00


Google удалил 49 расширений для Chrome, ворующих ключи от биткоин-кошельков

Разработчиками вредоносных программ, которые под видом утилит для работы с криптовалютными кошельками попали в магазин Google Web Store, предположительно были российские хакеры. Об этом сообщил исследователь проблем безопасности Гарри Денли.

2020-4-16 13:22


Google восстановил доступ к кошельку MetaMask в магазине приложений

В магазине приложений Google Play вновь появился Ethereum-кошелек MetaMask. Его создатели сообщили, что Google принял решение после тщательных раздумий. Happy New Year! Upon careful consideration, Google has permitted The MetaMask mobile app back on the Google Play (Android) store! Thanks to all the believers in an open web for speaking out in our support! https://t.co/Z8KOCtvHq0 […]

2020-1-2 11:31


Google восстановил доступ к Ethereum-кошельку MetaMask в магазине приложений

В магазине приложений Google Play вновь появился Ethereum-кошелек MetaMask. Его создатели сообщили, что Google принял решение после тщательных раздумий. Happy New Year! Upon careful consideration, Google has permitted The MetaMask mobile app back on the Google Play (Android) store! Thanks to all the believers in an open web for speaking out in our support! https://t.co/Z8KOCtvHq0 […]

2020-1-2 11:31


Фото:

Indie developers get death threats over decision to make Ooblets an Epic exclusive

A pair of indie developers became the targets of death threats and hate speech after they decided to make their game an Epic Store exclusive. It begs the question: has this Epic vs the greater PC gaming community thing gone a little too far? Husband and wife team Rebecca Cordingley and Ben Wasser have been developing a darling life sim game called Ooblets since 2016.

2019-8-7 04:00


Фото:

Большая часть расширений для Chrome имеет меньше 1000 установок

Аналитики из компании Extension Monitor выяснили, что большинство расширений для браузера Chrome не пользуются популярностью, а почти 20 000 инструментов даже никогда не устанавливались. По их мнению, своеобразный город-призрак из неактуальных расширений возник из-за того, что любой желающий может загрузить в Web Store свой продукт.

2019-8-5 14:42


Фото:

Instagram and WhatsApp get a ‘from Facebook’ stamp to remind you who’s boss

To be honest, I’m kind of impressed Facebook held out this long. After buying WhatsApp and Instagram several years ago, Facebook has decided it’s time to let everyone know who’s in charge. A report from The Information details Facebook plans to change the names of the apps to ‘Instagram from Facebook‘ and ‘WhatsApp from Facebook.

2019-8-5 02:35


Фото:

There’s now a cryptoart lottery using Bitcoin blockchain to pick a winner — and it’s brilliant

We’ve heard about auctions using blockchain to record sales of expensive works of art. We’ve seen the abstract musings of the cryptoart world, too. But what about a cryptoart charity auction that’s using blockchain to pick the winner? Well, an initiative being run by a trio of firms including cryptocurrency swap exchange service ChangeAngel, crypto-clothing store CryptoBantam, and cryptoartist Trevor Jones, is doing just that.

2019-8-2 11:27


Фото:

Facebook open-sources APIs to help fight child exploitation and terrorist propaganda

Facebook today announced it’s open-sourcing two technologies that help it curb the spread of problematic content like child exploitation, terrorist propaganda, or graphic violence online. These technologies aid the social network in detecting identical and nearly identical photos and video in order to weed out content that’s been flagged as being in violation of its policies.

2019-8-2 08:50


Google has removed 7 ‘stalkerware’ apps from its Play Store

For the ongoing series, Code Word, we’re exploring if — and how — technology can protect individuals against sexual assault and harassment, and how it can help and support survivors. Google has pulled seven tracking apps from the Play Store after Avast, a cybersecurity company, found they allowed people to stalk on their employees, children, or partner.

2019-7-18 17:39


Фото:

It’s 2019 and Google still can’t keep malware out of its Android app store

Google appears to have a problem with stopping malicious apps from sneaking into the Play Store. In what appears to yet another case of malware disguised as a legitimate app, security researchers from Symantec have found a new app that advertised itself as an unofficial version of Telegram messaging app — only to push malicious websites in the background.

2019-7-16 14:40