19 Malicious Chrome and Edge Extensions Found Stealing Crypto Wallets
Researchers have identified 19 malicious browser extensions for Chrome and Edge containing code designed to steal cryptocurrency wallet secrets and drain funds.

Cybersecurity researchers have uncovered a significant threat targeting cryptocurrency users through malicious browser extensions. A total of 19 extensions, 18 for Google Chrome and one for Microsoft Edge, were found to contain code capable of stealing wallet secrets and draining funds. These extensions were published over the last six months, with evidence suggesting the malicious campaign has been active since at least February 2024.
The operation, tracked by Socket under the name "Superior," involves a sophisticated modus operandi. Threat actors either acquire legitimate extensions with existing user bases or publish clean versions of new extensions. Once these extensions gain traction and accumulate downloads, the malicious code is introduced via an updated version. Of the 19 identified extensions, 14 were created by the threat actor, while the remaining five were purchased from their original developers.
This campaign appears to be broader than previously understood, with some aspects documented by DomainTools Investigations in May 2025. At that time, threat actors were observed creating fake websites that mimicked legitimate services, productivity tools, ad analysis assistants, VPNs, and financial utilities to lure users into installing malicious extensions from the Chrome Web Store. The extensions typically offer seemingly legitimate functionality while also connecting to malicious servers to exfiltrate user data and receive commands.
One of the most impactful extensions identified is "Enable Right Click & Copy — Smart Unlock + OCR," which has collectively garnered 80,000 installs across both Chrome and Edge browsers. Each of these malicious extensions is capable of establishing persistent WebSocket connections to command-and-control (C2) servers. The threat actors can dynamically rotate C2 endpoints and exfiltration channels, allowing them to distribute victims across different infrastructure and reduce the risk of detection.
The malicious code embedded within these extensions is designed to strip Content Security Policy (CSP) headers from web pages, enabling the injection of JavaScript modules. A total of 16 such modules have been identified, covering functionalities like multi-chain wallet draining, hardware wallet seed-phrase harvesting, cryptocurrency exchange and wallet account harvesting, universal credential or form grabbing, social media account stealing (Facebook, LinkedIn), browser history theft, and a "ClickFix" module that lures users into downloading fake browser updates.
The specific threat actor behind this campaign remains unknown, but their ability to operate undetected for over two years indicates a highly capable and organized group. The tactic of acquiring legitimate extensions and then updating them with malicious code is particularly concerning, as it leverages the trust users place in established applications and Chrome's default auto-update feature.
This discovery highlights the persistent threat posed by malicious browser extensions, especially within the cryptocurrency ecosystem. Users are advised to exercise extreme caution when installing new extensions, to review permissions carefully, and to only download extensions from trusted sources. Regularly auditing installed extensions and monitoring cryptocurrency wallet activity can also help mitigate potential losses.