Google Removes 49 Malicious Chrome Extensions That Stole Crypto Wallet Private Keys

Google Removes 49 Malicious Chrome Extensions That Stole Crypto Wallet Private Keys

N
News Editor 01
2026-07-08 20:40:13
Google pulled 49 Chrome browser extensions that were secretly stealing cryptocurrency wallet private keys and mnemonic phrases. Targeting Ledger, Trezor, and other wallets, the extensions were reported and removed within 24 hours.
Googlecryptocurrencywallet securityChrome extensionprivate key theft

Google has removed 49 malicious Chrome browser extensions that were found to be stealing private keys from cryptocurrency wallets. The discovery was made by Harry Denley, Director of Security at Mycrypto, an open-source tool for generating ether wallets and handling ERC20 tokens. These extensions posed as legitimate crypto wallet plugins but contained malicious code designed to exfiltrate private keys, mnemonic phrases, and keystore files.

How the Malicious Extensions Worked

Denley revealed that the extensions collected sensitive data entered during various wallet configuration steps and sent it to attacker-controlled servers or Google Forms. Some of the fraudulent extensions even had a network of fake users rating them with five stars or positive feedback to appear legitimate. According to Denley, the extensions appeared to be the work of one person or a group of people likely based in Russia. The malicious extensions began appearing slowly in February and rapidly increased releases through April. Once reported to Google, they were removed within 24 hours.

Targeted Wallets

The malicious extensions targeted eight popular cryptocurrency wallets: Ledger, Trezor, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and KeepKey. The most targeted wallet was Ledger, attacked by 57% of the malicious extensions, followed by MyEtherWallet (22%), Trezor (8%), Electrum (4%), KeepKey (4%), and Jaxx (2%). During his test, Denley sent funds to a few addresses and entered some secrets. He found that the funds sent were not automatically swept, concluding that the attackers were either only interested in high-value accounts or had to manually empty the addresses.

Security Implications and Recommendations

This incident highlights the ongoing risks in the crypto ecosystem, especially from browser extensions. Users are advised to only download wallet applications from official sources and avoid unnecessary browser extensions. Enabling hardware wallet multi-factor authentication and storing private keys offline are effective measures to mitigate such threats. Google has reiterated its commitment to improving extension review processes, but user vigilance remains critical. As of now, the extensions have been removed, but similar threats may resurface. Cryptocurrency users should stay updated on security advisories and regularly check their installed extensions for suspicious activity.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.