TechNewsReel
Live

Socket Finds 19 Malicious Chrome and Edge Extensions Targeting Crypto Wallets

Researchers identify a coordinated campaign of browser extensions designed to steal wallet secrets and drain digital assets.

TechNewsReel Newsroom · August 28, 2026

Cybersecurity researchers at Socket have identified 19 malicious browser extensions designed to steal cryptocurrency wallet secrets and drain user funds. The discovery reveals a coordinated effort to exploit the browser extension ecosystem to target digital asset holders.

According to Socket, the cluster consists of 18 extensions for Google Chrome and one for Microsoft Edge. These tools were published over the last six months and specifically target wallet secrets stored in browser local storage or managed by other extensions. Researchers noted that the extensions share significant similarities in their malicious code and operational techniques, suggesting they are part of a single, coordinated campaign or framework.

The Extension Attack Vector

Malicious browser extensions have become a frequent vector for supply chain attacks. Attackers often masquerade their software as legitimate, useful tools to trick users into granting high-level permissions. Once installed, these extensions can monitor browser activity, access sensitive local storage, and intercept data from other installed plugins, making them ideal for targeting cryptocurrency users who rely on browser-based wallets.

Industry Implications

This campaign highlights a persistent vulnerability in the browser extension marketplaces. Despite existing review processes, malicious code can bypass initial screenings and remain active for months before detection. For the cryptocurrency industry, this underscores the inherent risk of managing private keys or wallet secrets within a browser environment, where a single compromised extension can lead to the total loss of digital assets.

Future Outlook

As attackers refine their tradecraft to evade automated detection, the reliance on marketplace reviews remains a critical point of failure. Security experts continue to monitor for similar clusters of extensions that utilize shared codebases to scale their attacks. Users are encouraged to audit their installed extensions and limit the permissions granted to third-party tools to mitigate the risk of wallet drainage.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.