Google has removed 49 malicious browser extensions that were masquerading as legitimate cryptocurrency wallet tools while secretly stealing users' private keys, mnemonic phrases, and keystore files. The discovery was made public on Tuesday by security researcher Harry Denley, director of security at Mycrypto, an open-source tool for Ethereum wallet generation and ERC20 token management.
How the Malicious Extensions Worked
Denley detailed in a blog post that the 49 extensions appeared identical to genuine wallet extensions but contained hidden malicious code. When users entered sensitive data during wallet configuration steps, the code intercepted the information and transmitted it to attacker-controlled servers or Google Forms. Some of these fraudulent extensions even featured networks of fake user accounts that gave them five-star ratings and positive feedback to build credibility. Denley believes the attackers are likely a single person or group operating from Russia.
Targeted Wallets and Attack Distribution
The wallets targeted by the malicious extensions include Ledger, Trezor, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and Keepkey. Ledger was the most heavily targeted, accounting for 57% of the malicious extensions, followed by MyEtherWallet (22%), Trezor (8%), Electrum (4%), Keepkey (4%), and Jaxx (2%). During his investigation, Denley sent funds to a few addresses and entered secrets to observe behavior. He found that the funds were not automatically swept, suggesting that the attackers either focus on high-value accounts or manually empty addresses.
Timeline and Google's Response
The malicious extensions began appearing on the Chrome Web Store in February 2020, with a slow initial trickle that rapidly accelerated through April. Denley reported the threats to Google, and all 49 extensions were removed within 24 hours. Nevertheless, the incident highlights the persistent risk of browser-based crypto wallet tools. Users are advised to verify extension sources, install only from official wallet websites or trusted developers, and regularly review their list of installed extensions.
This event serves as a stark reminder that even extensions found in official app stores can be compromised. Maintaining good security hygiene—such as using hardware wallets, avoiding entering private keys in browsers, and keeping software updated—remains essential for safeguarding digital assets.

