Fake Crypto Wallet Ranks Fourth on Chrome Web Store While Stealing User Funds

Fake Crypto Wallet Ranks Fourth on Chrome Web Store While Stealing User Funds
фото показано с : bravenewcoin.com

2025-11-15 01:39

The malicious extension called “Safery: Ethereum Wallet” appears legitimate at first glance. It ranks just behind trusted wallets like MetaMask when users search for “Ethereum Wallet” on the Chrome store. However, security researchers have discovered it contains hidden code designed to steal cryptocurrency from anyone who uses it.

How the Scam Works

The fake wallet uses a sophisticated method to steal user seed phrases. When someone creates a new wallet or imports an existing one, the extension secretly encodes their 12 or 24-word seed phrase into fake Sui blockchain addresses.

The malicious code then sends tiny transactions worth 0.000001 SUI tokens to these encoded addresses. To outside observers, these look like normal blockchain activity. But the attackers can decode these transactions to recover the victim’s complete seed phrase and gain full control of their crypto wallet.

Source: socket.dev

Socket’s security team discovered this extension and explained how it works. “The mnemonic leaves the browser concealed inside normal looking blockchain transactions,” their report states. This makes the theft nearly impossible to detect using traditional security methods.

Warning Signs Users Missed

Several red flags should have warned users away from this fake wallet. The extension has zero user reviews and contains grammatical errors in its description. It also lacks an official website and lists only a Gmail address for developer contact.

The extension was initially uploaded on September 29, 2025, with the most recent update on November 12, 2025. Despite these obvious warning signs, the fake wallet managed to climb to fourth place in search rankings, potentially exposing thousands of users to theft.

Security experts say this high ranking gives the malicious extension “immediate visibility and a veneer of legitimacy to unsuspecting users.” This positioning dramatically increases the chances that people will download and use the fake wallet before discovering its true nature.

Growing Threat to Crypto Users

Browser extension scams represent a growing problem in the cryptocurrency space. Industry data shows that wallet-related scams drained over $500 million in 2024 alone, with browser extensions becoming an increasingly popular attack vector according to industry reports.

The timing of this discovery is particularly concerning. AI-powered crypto tools are becoming more popular, with AI agent tokens growing 222% in late 2024. As more people seek convenient ways to manage their cryptocurrency, they become more vulnerable to fake tools that promise easy solutions.

This fake wallet represents a new level of sophistication in crypto theft. Unlike simple phishing websites that might be obvious scams, this extension appeared in Google’s official store alongside legitimate options. The blockchain-based method of stealing seed phrases is also innovative, using the transparency of blockchain networks against users.

Current Status and Response

As of November 14, 2025, the Safery extension remains available for download on the Chrome Web Store. Socket reported the malicious extension to Google’s security team and requested removal of the publisher account, but the extension has not yet been taken down.

The extension’s continued availability highlights ongoing problems with app store security reviews. While Google has policies in place to prevent malicious software, sophisticated scams like this one can slip through the approval process and remain available for weeks or months.

Security researchers warn that this technique could spread to other blockchain networks. The method works by exploiting the public nature of blockchain transactions, meaning similar attacks could target users of Solana, Ethereum, or other cryptocurrency networks.

How to Stay Safe

Users can protect themselves by following several key security practices. Always research any crypto wallet or extension before installation. Look for established tools with thousands of positive reviews and verified developers.

Legitimate crypto wallets like MetaMask undergo regular security audits by professional firms. They also maintain official websites with detailed documentation and support resources. Fake wallets typically lack these features.

Never share seed phrases with anyone, and be suspicious of any software that asks for your complete seed phrase during normal operation. Legitimate wallets only require seed phrases during initial setup or recovery processes.

Monitor your wallet transactions regularly for any unexpected activity. Even tiny transactions could indicate that your seed phrase has been compromised. Use blockchain explorers to review all incoming and outgoing transactions from your addresses.

Enable two-factor authentication on crypto exchanges and wallet services whenever possible. While this won’t protect against seed phrase theft, it adds an extra security layer for online accounts.

The Digital Wild West Continues

This incident shows that cryptocurrency remains a target-rich environment for scammers. Despite years of warnings about security risks, fake wallets and malicious extensions continue to fool users and steal millions of dollars.

The sophistication of this particular scam – using blockchain transactions to hide stolen data – suggests that attackers are constantly developing new methods to stay ahead of security measures. Users must remain vigilant and stick to well-established, audited tools when managing their cryptocurrency assets.

origin »

Atomic Wallet Coin (AWC) на Currencies.ru

$ 0.086028 (+0.00%)
Объем 24H $0
Изменеия 24h: -0.66 %, 7d: 5.09 %
Cегодня L: $0.086028 - H: $0.086028
Капитализация $912.212k Rank 2128
Цена в час новости $ 0.0840878 (2.31%)

web store stealing fake chrome wallet crypto

web store → Результатов: 126


Фальшивый Ethereum-кошелек в Chrome Web Store крадет сид-фразы

Платформа безопасности блокчейна Socket предупредила о новой угрозе, которая маскируется под надежный кошелек. Расширение для Ethereum в Chrome Web Store занимает четвертое место в поиске и крадет сид-фразы пользователей через хитрую схему с микротранзакциями.

2025-11-14 10:27


SimpleHold Review – Is SimpleHold A Legit & Safe Crypto Wallet?

In this article, we will review what is Simplehold wallet is and why you should think about installing it as your go to web/mobile crypto wallet. What Is SimpleHold Security is of great importance when dealing with cryptocurrencies; that is why it is of ultimate importance to choose a secure and reliable wallet to store […] The post SimpleHold Review – Is SimpleHold A Legit & Safe Crypto Wallet? appeared first on CaptainAltcoin.

2022-4-5 18:22


Amazon предложил услуги по облачному майнингу криптовалюты Chia

Технологический гигант Amazon представил решение для майнинга криптовалюты Chia на своей платформе облачных вычислений Amazon Web Services (AWS). Об этом сообщает The Block. В кратком руководстве компания рассказывает об особенностях добычи Chia и предлагает несколько вариантов использования их облачной системы для этих целей: вычислительные ресурсы Amazon Elastic Compute Cloud, которые обладают большим объемом памяти и высокочастотным процессором;хранилище Amazon Elastic Block Store с жесткими дисками большой емкости с улучшенными возможностями чтения и записи;объектное хранилище большой емкости и недорогое пространство Amazon Simple Storage Service для хранения большого количества файлов.

2021-5-8 13:18


LEAD Wallet Launches Its Super Simple Application; Even Your Grandma Would Be Able to Use It

PRESS RELEASE. Lead Wallet, a new crypto wallet application, has officially been launched on Google Play Store, and it will also launch its iOS and web version soon. This crypto wallet application is different from other existing wallet apps because it aims to be a super simple crypto app that most people would find easy […] The post LEAD Wallet Launches Its Super Simple Application; Even Your Grandma Would Be Able to Use It appeared first on Bitcoin News.

2020-12-17 20:00


Фото:

Orchid: Bringing Decentralization to VPNs

Whenever we browse the web, read news online, or purchase a new pair of glasses from an e-commerce store, we leave traces. These traces sometimes show us content that actually provides us with value, but more often the information we leave is used in concerning ways with scandals like Cambridge Analytica just forming the tip […] The post Orchid: Bringing Decentralization to VPNs appeared first on Bitcoin News.

2020-8-5 17:00


Google удалил 49 расширений для Chrome, ворующих ключи от биткоин-кошельков

Разработчиками вредоносных программ, которые под видом утилит для работы с криптовалютными кошельками попали в магазин Google Web Store, предположительно были российские хакеры. Об этом сообщил исследователь проблем безопасности Гарри Денли.

2020-4-16 13:22


Google восстановил доступ к кошельку MetaMask в магазине приложений

В магазине приложений Google Play вновь появился Ethereum-кошелек MetaMask. Его создатели сообщили, что Google принял решение после тщательных раздумий. Happy New Year! Upon careful consideration, Google has permitted The MetaMask mobile app back on the Google Play (Android) store! Thanks to all the believers in an open web for speaking out in our support! https://t.co/Z8KOCtvHq0 […]

2020-1-2 11:31


Google восстановил доступ к Ethereum-кошельку MetaMask в магазине приложений

В магазине приложений Google Play вновь появился Ethereum-кошелек MetaMask. Его создатели сообщили, что Google принял решение после тщательных раздумий. Happy New Year! Upon careful consideration, Google has permitted The MetaMask mobile app back on the Google Play (Android) store! Thanks to all the believers in an open web for speaking out in our support! https://t.co/Z8KOCtvHq0 […]

2020-1-2 11:31


Фото:

Venezuela may have Bitcoin and Ethereum, but it’s unsure how it can use them

The central bank of Venezuela is reportedly looking into whether it can store cryptocurrencies in its coffers, Bloomberg reports citing four anonymous individuals close to the matter. According to the report the bank‘s investigation follows a request by Petroleos de Venezuela SA (PSDV) – the country’s state-owned oil and natural gas company – which is apparently looking to send Bitcoin and Ethereum to the central bank.

2019-9-26 18:52


Фото:

Android users suckered for $100s by basic calculator and QR scanning apps

If all the different types of malware that find a way to sneak into the Google Play Store wasn’t enough, here’s another nasty surprise. A new category of apps called “Fleeceware” has been unearthed on the app distribution platform; these apps were found to abuse the Play Store policies and grossly charge users hundreds of dollars for mundane services like calculators and QR code scanners.

2019-9-26 09:30


Фото:

VPN apps with 500M+ installs caught serving disruptive ads to Android users

Google Play Store has a malware problem. And it doesn’t seem to go away despite the company’s best efforts to rein in sketchy apps. In a yet another instance of Android adware, New Zealand-based independent security researcher Andy Michael found four Android VPN apps with cumulative downloads of over 500 million that not only serve ads while running the background, but are also placed outside the apps, including the home screen.

2019-9-20 14:53