The post Security Researchers Uncovered Dubious “Safery” Crypto Wallet Chrome Store appeared on BitcoinEthereumNews.com. Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.   The extension is called “Safery: Ethereum Wallet” and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets.  However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.   “Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads.  Safety Wallet promo images. Source: Chrome Store Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt.  Chrome store search results. Source: Chrome Store The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user. In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time.  In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.   “When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding:  “By decoding the recipients, the threat… The post Security Researchers Uncovered Dubious “Safery” Crypto Wallet Chrome Store appeared on BitcoinEthereumNews.com. Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.   The extension is called “Safery: Ethereum Wallet” and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets.  However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.   “Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads.  Safety Wallet promo images. Source: Chrome Store Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt.  Chrome store search results. Source: Chrome Store The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user. In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time.  In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.   “When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding:  “By decoding the recipients, the threat…

Security Researchers Uncovered Dubious “Safery” Crypto Wallet Chrome Store

For feedback or concerns regarding this content, please contact us at [email protected]

Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.  

The extension is called “Safery: Ethereum Wallet” and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets. 

However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.  

“Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads. 

Safety Wallet promo images. Source: Chrome Store

Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt. 

Chrome store search results. Source: Chrome Store

The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user.

In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time. 

In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.  

“When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding: 

How crypto users can avoid scam extensions

While this malicious extension appears high in the search results, there are some clear signs that it lacks legitimacy. 

Related: Scammers posed as Australian police to steal crypto, authorities warn

The extension has zero reviews, very limited branding, grammatical mistakes in some of the branding, no official website, and links to a developer using a Gmail account.

It is important for people to do significant research before they deal with any blockchain platform and tool, be extremely careful with seed phrases, have solid cybersecurity practices, and research well-established alternatives with verified legitimacy. 

Given that this extension also sends microtransactions, it is essential to consistently monitor and identify wallet transactions, as even small transactions could be harmful. 

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack

Source: https://cointelegraph.com/news/malicious-crypto-wallet-google-extension-steals-seed-phrases?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50
ZEC Rally and G Coin — Two Altcoin Setups Worth Watching

ZEC Rally and G Coin — Two Altcoin Setups Worth Watching

The post ZEC Rally and G Coin — Two Altcoin Setups Worth Watching appeared on BitcoinEthereumNews.com. The crypto market has started the week on a bullish footing
Share
BitcoinEthereumNews2026/03/19 00:58
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32