BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious “Safery” Chrome Wallet Steals Ethereum Seed Phrases

  • A malicious Chrome extension named Safery: Ethereum Wallet disguises itself as a secure Ethereum wallet but steals users’ seed phrases.
  • The extension encodes stolen seed phrases into synthetic Sui Blockchain addresses and broadcasts micro-transactions to exfiltrate data.
  • Seed phrase theft occurs without a command-and-control server, allowing the attacker to decode transactions later and access victims’ funds.
  • The extension has been available on the Chrome Web Store since September 29, 2025, and was updated as recently as November 12, 2025.
  • Users should prefer trusted wallet extensions and defenders should scan for suspicious behaviors such as mnemonic encoding and on-chain activity during wallet import.

A harmful Chrome browser extension called Safery: Ethereum Wallet has been discovered, posing as a legitimate tool for managing Ethereum cryptocurrency since its release on September 29, 2025. This extension claims to offer secure wallet management but secretly captures users’ wallet seed phrases, critical credentials that allow access to crypto assets. Despite updates as recent as November 12, 2025, the extension remains available on the Chrome Web Store.

- Advertisement -

The extension operates by encoding seed phrases into counterfeit Sui blockchain wallet addresses, then sending minute transactions of approximately $0.000001 worth of SUI tokens from a threat actor-controlled wallet to those addresses. This method hides sensitive data inside apparently normal blockchain activity without the need for a command-and-control (C2) server. According to security researcher Kirill Boychenko, this technique enables attackers to monitor the blockchain for these transactions and later decode the recipient addresses to reconstruct stolen seed phrases.

This vector allows threat actors to easily switch blockchain networks and remote procedure call (RPC) endpoints, complicating detection efforts that rely on monitoring specific domains, URLs, or extension IDs. Security analysts at Koi Security detailed how the extension sends micro-transactions to fake addresses to steal users’ mnemonic phrases and subsequently drain victims’ funds.

To mitigate risks, users are advised to use well-known and trusted wallet extensions. Security professionals are encouraged to detect and block extensions that generate synthetic blockchain addresses, encode mnemonics, or conduct unauthorized on-chain operations during wallet creation or import. Boychenko emphasizes treating unexpected blockchain RPC calls in browsers as high-risk signals, particularly when extensions advertise support for only a single blockchain network.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Nears $64K Despite Iran Tensions, Trader Caution

Bitcoin regained the $64,000 level despite renewed geopolitical tensions involving the US, Iran, and...

Micron’s AI HBM Boom: $435 to $1,750 Price Target Split

Wall Street's 2026 price targets for Micron stock show extreme divergence, ranging from around...

AI Chatbots May Reinforce Delusions in Vulnerable Users

Researchers propose a new "amplification spiral" framework to explain how AI chatbots could reinforce...

Bitcoin Plunges 50%, Sparking Fears of Imminent Market Collapse

Bitcoin's price has fallen to half its October 2025 peak, sparking fears of a...

Dash Eyes Philippines for Crypto Payments Expansion

Dash is exploring the Philippines as a target market for its low-cost crypto payment...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading