According to ChainCatcher news, as disclosed by the GoPlus Chinese community, a malicious Chrome extension named “Safery: Ethereum Wallet” has been found to be stealing user assets. This extension was released on November 12, 2024, disguised as a simple and secure Ethereum wallet, but it contains a built-in backdoor. The attack method is highly covert: the malicious extension encodes user mnemonic phrases into Sui addresses and broadcasts microtransactions from a Sui wallet controlled by the attacker to steal the mnemonic phrases. The attacker's email is kifagusertyna@gmail[.]com. Currently, this malicious extension has not been delisted from the Chrome Web Store.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Malicious Chrome extension "Safery: Ethereum Wallet" disguised as an ETH Wallet to steal users' mnemonic phrases.
According to ChainCatcher news, as disclosed by the GoPlus Chinese community, a malicious Chrome extension named “Safery: Ethereum Wallet” has been found to be stealing user assets. This extension was released on November 12, 2024, disguised as a simple and secure Ethereum wallet, but it contains a built-in backdoor. The attack method is highly covert: the malicious extension encodes user mnemonic phrases into Sui addresses and broadcasts microtransactions from a Sui wallet controlled by the attacker to steal the mnemonic phrases. The attacker's email is kifagusertyna@gmail[.]com. Currently, this malicious extension has not been delisted from the Chrome Web Store.