Google Removes 49 Chrome Extensions Found Stealing Crypto Wallet Private Keys

Google Removes 49 Chrome Extensions Found Stealing Crypto Wallet Private Keys

N
News Editor 01
2026-07-08 20:46:14
Google removed 49 malicious Chrome extensions posing as crypto wallet tools after a security researcher found they were stealing private keys, seed phrases, and keystore files.
GoogleChrome ExtensionsCrypto WalletsPrivate KeysCybersecurity

Google has removed 49 malicious Chrome browser extensions that were disguised as legitimate cryptocurrency wallet tools and used to steal highly sensitive user data. According to the reported findings, the fake extensions targeted users of major wallets including Ledger, Trezor, Jaxx, Electrum, Myetherwallet, Metamask, Exodus, and Keepkey. Their primary objective was to capture private keys, mnemonic seed phrases, and keystore files from unsuspecting users.

Security Researcher Exposed the Campaign

The campaign was disclosed by Harry Denley, director of security at Mycrypto, an open-source tool for generating ether wallets and managing ERC-20 tokens. Denley said the 49 Chrome extensions were designed to impersonate legitimate wallet software while embedding malicious code capable of harvesting secrets entered during wallet setup and recovery procedures.

Rather than relying on sophisticated wallet-draining automation alone, the extensions reportedly gathered information submitted by users at different configuration stages and then transmitted that data to attacker-controlled infrastructure. In some cases, the stolen information was sent to one of the attacker’s servers; in others, it was submitted through a Google Form. The use of simple collection channels highlights how effective social engineering can be when users are tricked into trusting a fraudulent interface.

Fake Reviews Helped the Extensions Look Legitimate

One notable detail in the report is that some of the malicious extensions appeared to be supported by a network of fabricated user accounts leaving five-star ratings and positive feedback. This tactic likely helped the extensions gain credibility in the Chrome Web Store, where users often rely on reviews, ratings, and visual similarity to identify trustworthy software.

By combining familiar wallet branding with positive-looking social proof, the operators increased the chances that users would install the fake tools and enter highly sensitive credentials. In the crypto sector, where control of private keys equals control of funds, such deception can be especially dangerous because a single compromised seed phrase may expose the entirety of a wallet’s holdings.

Ledger Was the Most Frequently Targeted Wallet

Among the wallet brands imitated by the malicious extensions, Ledger was the most targeted, accounting for 57% of the identified fake plugins. Myetherwallet ranked second at 22%. Trezor accounted for 8%, while Electrum and Keepkey each represented 4%, and Jaxx 2%.

This distribution suggests that attackers prioritized brands with strong recognition and broad user adoption. Well-known wallet names are more likely to attract downloads, and users searching quickly for browser-based wallet tools may be vulnerable to convincing lookalike products. The targeting pattern also reflects how criminals often exploit the trust built by established wallet providers without ever breaching the providers themselves.

Private Keys, Seed Phrases, and Keystore Files Were at Risk

The reported malicious behavior was particularly serious because the extensions did not merely request broad browser permissions or display misleading prompts. They were built to collect the exact forms of information that allow direct access to crypto assets: private keys, mnemonic phrases, and keystore files. Once such data is exposed, wallet security is effectively broken, regardless of whether the user continues to control the original device.

In many cryptocurrency systems, there is no centralized mechanism to reverse unauthorized transfers. That means the theft of recovery credentials can lead to permanent loss of funds if attackers choose to act on the stolen information. Even if an account is not drained immediately, the compromise can remain latent until a later time.

Researchers Observed a Gradual Build-Up Before Rapid Growth

Denley said the malicious extensions started appearing in the Chrome store in February and then increased sharply through April. That timeline suggests an operation that initially scaled gradually before accelerating, potentially as the operators refined their methods or saw early success. The ability to publish multiple fraudulent extensions under different wallet names also points to a repeatable pattern rather than isolated incidents.

Based on the observed similarities, Denley assessed that the extensions appeared to be the work of one person or one coordinated group, likely based in Russia. However, the report did not present definitive attribution beyond that assessment.

Funds Were Not Always Drained Immediately

During testing, Denley reportedly sent funds to several addresses and entered some secrets into the extensions. He found that the funds were not automatically swept out. From this, he concluded that the attackers may have been interested primarily in higher-value accounts, or that they needed to manually empty compromised addresses rather than using an always-on automated draining system.

This detail matters because it shows that immediate theft is not the only threat model. Attackers can silently collect credentials first and decide later when and whether to exploit them. For users, the absence of instant fund movement should not be treated as proof that a wallet is safe after secrets have already been exposed.

Google Removed the Extensions Within 24 Hours of the Report

After the extensions were reported, Google removed them within 24 hours, according to the disclosed information. The takedown reduced immediate exposure for users browsing the Chrome Web Store, but the broader lesson is that platform moderation, while necessary, may not catch every malicious listing before damage occurs.

The incident underscores a recurring security challenge in crypto: attackers do not always need to break cryptography or compromise hardware. In many cases, simply convincing users to install a fake tool and type in their recovery information is enough. Because wallet credentials are so sensitive, users should treat any browser extension requesting seed phrases or private keys with extreme caution and verify software through official sources before installation.

More broadly, the case highlights the ongoing need for stronger vigilance around wallet impersonation, fake app listings, and extension-based attacks. For crypto users, the safest approach remains minimizing exposure of recovery data, confirming software authenticity through official channels, and understanding that branding, ratings, and store presence alone are not reliable guarantees of legitimacy.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.