The post Malicious Wallet on Chrome Ranks High and Steals User Crypto appeared on BitcoinEthereumNews.com. The malicious extension secretly encodes users’ seed phrases into Sui microtransactions, giving attackers the ability to drain wallets without detection. At the same time, Australian authorities warned that criminals have been impersonating police and exploiting official government systems to pressure victims into transferring their digital assets. Together, these cases reveal how scammers are now blending technical backdoors with social-engineering tactics to deceive even cautious users. Crypto users are cursed to treat unexpected communications with extreme suspicion. Malicious Wallet App Tricks Users Blockchain security firm Socket uncovered a dangerous new threat lurking in the Google Chrome Web Store: a malicious wallet extension called “Safery: Ethereum Wallet.” Although it presents itself as a reliable and secure tool for managing Ethereum-based assets, researchers found that the extension contains a sophisticated backdoor that is designed to steal users’ seed phrases and ultimately drain their crypto holdings. According to Socket’s report, the extension uses an unusually crafty method to export stolen seed phrases. When a user creates a new wallet or imports an existing one, the extension encodes their BIP-39 mnemonic into synthetic Sui-style addresses. It then broadcasts a microtransaction of just 0.000001 SUI from a wallet controlled by the attackers.  Safery: Ethereum Wallet  On the surface, the transaction looks harmless, but the destination addresses actually represent fragments of the user’s seed phrase. By decoding these addresses, the scammers can reconstruct the full mnemonic and access the victim’s assets whenever they choose. This makes the threat particularly dangerous because users may not notice anything suspicious. The extension behaves like a normal Ethereum wallet, offers familiar features, and even ranks fourth in Chrome’s search results for “Ethereum Wallet,” just behind legitimate platforms like MetaMask, Wombat and Enkrypt. That high placement increases the likelihood that unsuspecting users will install it, unaware of the risks. Search results for… The post Malicious Wallet on Chrome Ranks High and Steals User Crypto appeared on BitcoinEthereumNews.com. The malicious extension secretly encodes users’ seed phrases into Sui microtransactions, giving attackers the ability to drain wallets without detection. At the same time, Australian authorities warned that criminals have been impersonating police and exploiting official government systems to pressure victims into transferring their digital assets. Together, these cases reveal how scammers are now blending technical backdoors with social-engineering tactics to deceive even cautious users. Crypto users are cursed to treat unexpected communications with extreme suspicion. Malicious Wallet App Tricks Users Blockchain security firm Socket uncovered a dangerous new threat lurking in the Google Chrome Web Store: a malicious wallet extension called “Safery: Ethereum Wallet.” Although it presents itself as a reliable and secure tool for managing Ethereum-based assets, researchers found that the extension contains a sophisticated backdoor that is designed to steal users’ seed phrases and ultimately drain their crypto holdings. According to Socket’s report, the extension uses an unusually crafty method to export stolen seed phrases. When a user creates a new wallet or imports an existing one, the extension encodes their BIP-39 mnemonic into synthetic Sui-style addresses. It then broadcasts a microtransaction of just 0.000001 SUI from a wallet controlled by the attackers.  Safery: Ethereum Wallet  On the surface, the transaction looks harmless, but the destination addresses actually represent fragments of the user’s seed phrase. By decoding these addresses, the scammers can reconstruct the full mnemonic and access the victim’s assets whenever they choose. This makes the threat particularly dangerous because users may not notice anything suspicious. The extension behaves like a normal Ethereum wallet, offers familiar features, and even ranks fourth in Chrome’s search results for “Ethereum Wallet,” just behind legitimate platforms like MetaMask, Wombat and Enkrypt. That high placement increases the likelihood that unsuspecting users will install it, unaware of the risks. Search results for…

Malicious Wallet on Chrome Ranks High and Steals User Crypto

The malicious extension secretly encodes users’ seed phrases into Sui microtransactions, giving attackers the ability to drain wallets without detection. At the same time, Australian authorities warned that criminals have been impersonating police and exploiting official government systems to pressure victims into transferring their digital assets. Together, these cases reveal how scammers are now blending technical backdoors with social-engineering tactics to deceive even cautious users. Crypto users are cursed to treat unexpected communications with extreme suspicion.

Malicious Wallet App Tricks Users

Blockchain security firm Socket uncovered a dangerous new threat lurking in the Google Chrome Web Store: a malicious wallet extension called “Safery: Ethereum Wallet.” Although it presents itself as a reliable and secure tool for managing Ethereum-based assets, researchers found that the extension contains a sophisticated backdoor that is designed to steal users’ seed phrases and ultimately drain their crypto holdings.

According to Socket’s report, the extension uses an unusually crafty method to export stolen seed phrases. When a user creates a new wallet or imports an existing one, the extension encodes their BIP-39 mnemonic into synthetic Sui-style addresses. It then broadcasts a microtransaction of just 0.000001 SUI from a wallet controlled by the attackers. 

Safery: Ethereum Wallet 

On the surface, the transaction looks harmless, but the destination addresses actually represent fragments of the user’s seed phrase. By decoding these addresses, the scammers can reconstruct the full mnemonic and access the victim’s assets whenever they choose.

This makes the threat particularly dangerous because users may not notice anything suspicious. The extension behaves like a normal Ethereum wallet, offers familiar features, and even ranks fourth in Chrome’s search results for “Ethereum Wallet,” just behind legitimate platforms like MetaMask, Wombat and Enkrypt. That high placement increases the likelihood that unsuspecting users will install it, unaware of the risks.

Search results for ‘Ethereum wallet’

Socket explained  that both new and existing wallet users are vulnerable. Users who generate a fresh wallet through the extension effectively hand over their seed phrase immediately. Those who import an existing wallet expose their already-funded accounts, giving the attackers instant access to all assets tied to that mnemonic.

Despite its polished search ranking, several red flags reveal the extension’s lack of legitimacy. The listing has no reviews, minimal branding, glaring grammatical errors, no official website, and a developer linked only to a Gmail address. These are all signs of an unverified and potentially malicious tool.

Security experts warn that users should be extremely cautious with browser extensions, especially those involving seed phrases or wallet management. They advise researching tools thoroughly, sticking to well-established platforms with verified credibility, and maintaining strong cybersecurity practices. 

Additionally, because Safery’s attack method relies on microtransactions, users should regularly monitor their wallet activity and investigate any unexpected or unusual transactions, no matter how small. Overall, this discovery serves as a reminder that even seemingly minor actions  can open the door to serious financial loss if users are not vigilant.

Scammers Impersonate Aussie Police to Steal Crypto

Meanwhile, Australian authorities recently issued a fresh warning after uncovering a sophisticated scam in which criminals impersonated police officers and misused government systems to pressure victims into surrendering their cryptocurrency. 

According to the Australian Federal Police (AFP), scammers exploited ReportCyber — the official platform for filing cybercrime reports — by submitting reports about their intended victims. They later contacted those people while posing as law-enforcement officials and directed them to the legitimate government website to view the report, giving the scheme an alarming level of credibility.

AFP announcement

In one case, scammers told a victim they would soon hear from a representative of a cryptocurrency company. That second caller then tried to convince the target to transfer money from their wallet to an address controlled by the scammers. The AFP said the victim became suspicious and ended the call before any funds were lost.

Detective Superintendent Marie Andersson explained that the fraudsters reinforced their deception by mimicking real police verification steps, and even claimed that  the victim was named in an investigation after the arrest of a suspect linked to a crypto breach. 

The AFP urged Australians to stay cautious, particularly if they receive unexpected communication about a ReportCyber submission they did not file. They also explained that legitimate law-enforcement agencies will never request access to banking details, cryptocurrency accounts, wallet seed phrases, or any sensitive financial information.

The warning  was made as Australia is working on boosting its efforts to combat crypto-related crime. Earlier this year, regulators reported that over 14,000 scams were dismantled since mid-2023, with more than 3,000 involving digital assets. In Tasmania, authorities found that the top 15 users of crypto ATMs were all scam victims, and collectively lost about USD 1.6 million.

Source: https://coinpaper.com/12344/malicious-wallet-on-chrome-ranks-high-and-steals-user-crypto

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00821
$0.00821$0.00821
-3.06%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
Scaramucci Says Trump Memecoins Drained Altcoin Market, Yet Sees Bitcoin Reaching $150,000 by Year-End

Scaramucci Says Trump Memecoins Drained Altcoin Market, Yet Sees Bitcoin Reaching $150,000 by Year-End

Anthony Scaramucci, stated that the introduction of Trump coins in January 2025 had a negative impact on the cryptocurrency revolution.
Share
Coinstats2026/02/16 01:57
Solana Treasury Firm Holdings Could Double as Forward Industries Unveils $4 Billion Raise

Solana Treasury Firm Holdings Could Double as Forward Industries Unveils $4 Billion Raise

The post Solana Treasury Firm Holdings Could Double as Forward Industries Unveils $4 Billion Raise appeared on BitcoinEthereumNews.com. In brief Forward Industries, the largest publicly traded Solana treasury company, filed to raise $4 billion through an at-the-market equity offering to expand its SOL holdings. The company’s stock (FORD) fell 8.2% following the announcement, while the proceeds could more than double the $3.1 billion currently held in Solana treasuries. DeFi Development Corp. also registered a preferred stock offering with the SEC, following similar funding tactics used by Bitcoin treasury companies like MicroStrategy. Forward Industries, the newest and largest publicly traded Solana treasury company, has filed to raise $4 billion through an at-the-market equity offering. For the sake of comparison, this $4 billion raise is nearly the same size as Bitcoin treasury Strategy’s Stride preferred stock raise in July. And it’s double the size of the Strife preferred stock offering the company did in May. The proceeds would be used for working capital; pursuit of its Solana token strategy, and “the purchase of income-generating assets to grow its business,” the company said in a press release. Forward Industries declined to comment to Decrypt on what other income-generating assets it’s considering adding to its balance sheet.  As markets opened Wednesday morning, Forward saw its stock price take a dive. The shares, which trade under the FORD ticker on the Nasdaq, dipped to $31.29 before rebounding to $34.28 at the time of writing—marking a 8.2% fall for the session. If the company sells all the shares and spends the bulk of the proceeds on buying Solana, it could more than double the amount of SOL being held in treasuries. At the time of writing, there’s already $3.1 billion in Solana treasuries, according to crypto price aggregator CoinGecko. Users on Myriad, a prediction market owned by Decrypt parent company DASTAN, have been growing more confident that SOL will reach $250 sooner than…
Share
BitcoinEthereumNews2025/09/18 12:43