Google Removes 49 Malicious Chrome Extensions Targeting Crypto Wallets for Private Keys

Google Removes 49 Malicious Chrome Extensions Targeting Crypto Wallets for Private Keys

N
News Editor 01
2026-07-08 20:40:13
Google has taken down 49 Chrome extensions that posed as cryptocurrency wallet tools to steal users' private keys, mnemonic phrases, and keystore files. Ledger was the most targeted wallet (57%).
GoogleChrome extensioncryptocurrency walletprivate key theftsecurity vulnerability

Google has removed 49 malicious browser extensions that were masquerading as legitimate cryptocurrency wallet tools while secretly stealing users' private keys, mnemonic phrases, and keystore files. The discovery was made public on Tuesday by security researcher Harry Denley, director of security at Mycrypto, an open-source tool for Ethereum wallet generation and ERC20 token management.

How the Malicious Extensions Worked

Denley detailed in a blog post that the 49 extensions appeared identical to genuine wallet extensions but contained hidden malicious code. When users entered sensitive data during wallet configuration steps, the code intercepted the information and transmitted it to attacker-controlled servers or Google Forms. Some of these fraudulent extensions even featured networks of fake user accounts that gave them five-star ratings and positive feedback to build credibility. Denley believes the attackers are likely a single person or group operating from Russia.

Targeted Wallets and Attack Distribution

The wallets targeted by the malicious extensions include Ledger, Trezor, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and Keepkey. Ledger was the most heavily targeted, accounting for 57% of the malicious extensions, followed by MyEtherWallet (22%), Trezor (8%), Electrum (4%), Keepkey (4%), and Jaxx (2%). During his investigation, Denley sent funds to a few addresses and entered secrets to observe behavior. He found that the funds were not automatically swept, suggesting that the attackers either focus on high-value accounts or manually empty addresses.

Timeline and Google's Response

The malicious extensions began appearing on the Chrome Web Store in February 2020, with a slow initial trickle that rapidly accelerated through April. Denley reported the threats to Google, and all 49 extensions were removed within 24 hours. Nevertheless, the incident highlights the persistent risk of browser-based crypto wallet tools. Users are advised to verify extension sources, install only from official wallet websites or trusted developers, and regularly review their list of installed extensions.

This event serves as a stark reminder that even extensions found in official app stores can be compromised. Maintaining good security hygiene—such as using hardware wallets, avoiding entering private keys in browsers, and keeping software updated—remains essential for safeguarding digital assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.