The post Malicious Wallet on Chrome Ranks High and Steals User Crypto appeared on BitcoinEthereumNews.com. The malicious extension secretly encodes users’ seed phrases into Sui microtransactions, giving attackers the ability to drain wallets without detection. At the same time, Australian authorities warned that criminals have been impersonating police and exploiting official government systems to pressure victims into transferring their digital assets. Together, these cases reveal how scammers are now blending technical backdoors with social-engineering tactics to deceive even cautious users. Crypto users are cursed to treat unexpected communications with extreme suspicion. Malicious Wallet App Tricks Users Blockchain security firm Socket uncovered a dangerous new threat lurking in the Google Chrome Web Store: a malicious wallet extension called “Safery: Ethereum Wallet.” Although it presents itself as a reliable and secure tool for managing Ethereum-based assets, researchers found that the extension contains a sophisticated backdoor that is designed to steal users’ seed phrases and ultimately drain their crypto holdings. According to Socket’s report, the extension uses an unusually crafty method to export stolen seed phrases. When a user creates a new wallet or imports an existing one, the extension encodes their BIP-39 mnemonic into synthetic Sui-style addresses. It then broadcasts a microtransaction of just 0.000001 SUI from a wallet controlled by the attackers.  Safery: Ethereum Wallet  On the surface, the transaction looks harmless, but the destination addresses actually represent fragments of the user’s seed phrase. By decoding these addresses, the scammers can reconstruct the full mnemonic and access the victim’s assets whenever they choose. This makes the threat particularly dangerous because users may not notice anything suspicious. The extension behaves like a normal Ethereum wallet, offers familiar features, and even ranks fourth in Chrome’s search results for “Ethereum Wallet,” just behind legitimate platforms like MetaMask, Wombat and Enkrypt. That high placement increases the likelihood that unsuspecting users will install it, unaware of the risks. Search results for… The post Malicious Wallet on Chrome Ranks High and Steals User Crypto appeared on BitcoinEthereumNews.com. The malicious extension secretly encodes users’ seed phrases into Sui microtransactions, giving attackers the ability to drain wallets without detection. At the same time, Australian authorities warned that criminals have been impersonating police and exploiting official government systems to pressure victims into transferring their digital assets. Together, these cases reveal how scammers are now blending technical backdoors with social-engineering tactics to deceive even cautious users. Crypto users are cursed to treat unexpected communications with extreme suspicion. Malicious Wallet App Tricks Users Blockchain security firm Socket uncovered a dangerous new threat lurking in the Google Chrome Web Store: a malicious wallet extension called “Safery: Ethereum Wallet.” Although it presents itself as a reliable and secure tool for managing Ethereum-based assets, researchers found that the extension contains a sophisticated backdoor that is designed to steal users’ seed phrases and ultimately drain their crypto holdings. According to Socket’s report, the extension uses an unusually crafty method to export stolen seed phrases. When a user creates a new wallet or imports an existing one, the extension encodes their BIP-39 mnemonic into synthetic Sui-style addresses. It then broadcasts a microtransaction of just 0.000001 SUI from a wallet controlled by the attackers.  Safery: Ethereum Wallet  On the surface, the transaction looks harmless, but the destination addresses actually represent fragments of the user’s seed phrase. By decoding these addresses, the scammers can reconstruct the full mnemonic and access the victim’s assets whenever they choose. This makes the threat particularly dangerous because users may not notice anything suspicious. The extension behaves like a normal Ethereum wallet, offers familiar features, and even ranks fourth in Chrome’s search results for “Ethereum Wallet,” just behind legitimate platforms like MetaMask, Wombat and Enkrypt. That high placement increases the likelihood that unsuspecting users will install it, unaware of the risks. Search results for…

Malicious Wallet on Chrome Ranks High and Steals User Crypto

The malicious extension secretly encodes users’ seed phrases into Sui microtransactions, giving attackers the ability to drain wallets without detection. At the same time, Australian authorities warned that criminals have been impersonating police and exploiting official government systems to pressure victims into transferring their digital assets. Together, these cases reveal how scammers are now blending technical backdoors with social-engineering tactics to deceive even cautious users. Crypto users are cursed to treat unexpected communications with extreme suspicion.

Malicious Wallet App Tricks Users

Blockchain security firm Socket uncovered a dangerous new threat lurking in the Google Chrome Web Store: a malicious wallet extension called “Safery: Ethereum Wallet.” Although it presents itself as a reliable and secure tool for managing Ethereum-based assets, researchers found that the extension contains a sophisticated backdoor that is designed to steal users’ seed phrases and ultimately drain their crypto holdings.

According to Socket’s report, the extension uses an unusually crafty method to export stolen seed phrases. When a user creates a new wallet or imports an existing one, the extension encodes their BIP-39 mnemonic into synthetic Sui-style addresses. It then broadcasts a microtransaction of just 0.000001 SUI from a wallet controlled by the attackers. 

Safery: Ethereum Wallet 

On the surface, the transaction looks harmless, but the destination addresses actually represent fragments of the user’s seed phrase. By decoding these addresses, the scammers can reconstruct the full mnemonic and access the victim’s assets whenever they choose.

This makes the threat particularly dangerous because users may not notice anything suspicious. The extension behaves like a normal Ethereum wallet, offers familiar features, and even ranks fourth in Chrome’s search results for “Ethereum Wallet,” just behind legitimate platforms like MetaMask, Wombat and Enkrypt. That high placement increases the likelihood that unsuspecting users will install it, unaware of the risks.

Search results for ‘Ethereum wallet’

Socket explained  that both new and existing wallet users are vulnerable. Users who generate a fresh wallet through the extension effectively hand over their seed phrase immediately. Those who import an existing wallet expose their already-funded accounts, giving the attackers instant access to all assets tied to that mnemonic.

Despite its polished search ranking, several red flags reveal the extension’s lack of legitimacy. The listing has no reviews, minimal branding, glaring grammatical errors, no official website, and a developer linked only to a Gmail address. These are all signs of an unverified and potentially malicious tool.

Security experts warn that users should be extremely cautious with browser extensions, especially those involving seed phrases or wallet management. They advise researching tools thoroughly, sticking to well-established platforms with verified credibility, and maintaining strong cybersecurity practices. 

Additionally, because Safery’s attack method relies on microtransactions, users should regularly monitor their wallet activity and investigate any unexpected or unusual transactions, no matter how small. Overall, this discovery serves as a reminder that even seemingly minor actions  can open the door to serious financial loss if users are not vigilant.

Scammers Impersonate Aussie Police to Steal Crypto

Meanwhile, Australian authorities recently issued a fresh warning after uncovering a sophisticated scam in which criminals impersonated police officers and misused government systems to pressure victims into surrendering their cryptocurrency. 

According to the Australian Federal Police (AFP), scammers exploited ReportCyber — the official platform for filing cybercrime reports — by submitting reports about their intended victims. They later contacted those people while posing as law-enforcement officials and directed them to the legitimate government website to view the report, giving the scheme an alarming level of credibility.

AFP announcement

In one case, scammers told a victim they would soon hear from a representative of a cryptocurrency company. That second caller then tried to convince the target to transfer money from their wallet to an address controlled by the scammers. The AFP said the victim became suspicious and ended the call before any funds were lost.

Detective Superintendent Marie Andersson explained that the fraudsters reinforced their deception by mimicking real police verification steps, and even claimed that  the victim was named in an investigation after the arrest of a suspect linked to a crypto breach. 

The AFP urged Australians to stay cautious, particularly if they receive unexpected communication about a ReportCyber submission they did not file. They also explained that legitimate law-enforcement agencies will never request access to banking details, cryptocurrency accounts, wallet seed phrases, or any sensitive financial information.

The warning  was made as Australia is working on boosting its efforts to combat crypto-related crime. Earlier this year, regulators reported that over 14,000 scams were dismantled since mid-2023, with more than 3,000 involving digital assets. In Tasmania, authorities found that the top 15 users of crypto ATMs were all scam victims, and collectively lost about USD 1.6 million.

Source: https://coinpaper.com/12344/malicious-wallet-on-chrome-ranks-high-and-steals-user-crypto

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.01651
$0.01651$0.01651
+6.72%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Japanese Yen rises on safe-haven demand and intervention concerns

Japanese Yen rises on safe-haven demand and intervention concerns

The post Japanese Yen rises on safe-haven demand and intervention concerns appeared on BitcoinEthereumNews.com. The Japanese Yen (JPY) attracts some buyers at the
Share
BitcoinEthereumNews2025/12/22 11:49
GBP trades firmly against US Dollar

GBP trades firmly against US Dollar

The post GBP trades firmly against US Dollar appeared on BitcoinEthereumNews.com. Pound Sterling trades firmly against US Dollar ahead of Fed’s policy outcome The Pound Sterling (GBP) clings to Tuesday’s gains near 1.3640 against the US Dollar (USD) during the European trading session on Wednesday. The GBP/USD pair holds onto gains as the US Dollar remains on the back foot amid firm expectations that the Federal Reserve (Fed) will cut interest rates in the monetary policy announcement at 18:00 GMT. At the time of writing, the US Dollar Index (DXY), which tracks the Greenback’s value against six major currencies, holds onto losses near a fresh two-month low of 96.60 posted on Tuesday. Read more… UK inflation unchanged at 3.8%, Pound shrugs The British pound is unchanged on Wednesday, trading at 1.3645 in the European session. Today’s inflation report was a dour reminder that UK inflation remains entrenched. CPI for August was unchanged at 3.8% y/y, matching the consensus and its highest level since January 2024. Airfares decreased but this was offset by food and petrol prices. Monthly, CPI rose 0.3%, up from 0.1% in July and matching the consensus. Core CPI, which excludes volatile items such as food and energy, eased to 3.6% from 3.8%. Monthly, core CPI ticked up to 0.3% from 0.2%. The inflation report comes just a day before the Bank of England announces its rate decision. Inflation is almost double the BoE’s target of 2% and today’s release likely means that the BoE will not reduce rates before 2026. Read more… Source: https://www.fxstreet.com/news/pound-sterling-price-news-and-forecast-gbp-trades-firmly-against-us-dollar-ahead-of-feds-policy-outcome-202509171209
Share
BitcoinEthereumNews2025/09/18 01:50
Hong Kong proposes law allowing insurers to invest in crypto

Hong Kong proposes law allowing insurers to invest in crypto

The post Hong Kong proposes law allowing insurers to invest in crypto appeared on BitcoinEthereumNews.com. Hong Kong is weighing a cautious shift that could open
Share
BitcoinEthereumNews2025/12/22 12:42