TLDR A malicious Chrome extension called “Safery: Ethereum Wallet” ranks fourth in Chrome Web Store searches for Ethereum wallets The extension steals seed phrases by encoding them into fake Sui blockchain addresses and sending tiny transactions worth 0.000001 SUI Threat actors decode the recipient addresses from these microtransactions to reconstruct users’ seed phrases and drain [...] The post Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions appeared first on CoinCentral.TLDR A malicious Chrome extension called “Safery: Ethereum Wallet” ranks fourth in Chrome Web Store searches for Ethereum wallets The extension steals seed phrases by encoding them into fake Sui blockchain addresses and sending tiny transactions worth 0.000001 SUI Threat actors decode the recipient addresses from these microtransactions to reconstruct users’ seed phrases and drain [...] The post Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions appeared first on CoinCentral.

Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions

TLDR

  • A malicious Chrome extension called “Safery: Ethereum Wallet” ranks fourth in Chrome Web Store searches for Ethereum wallets
  • The extension steals seed phrases by encoding them into fake Sui blockchain addresses and sending tiny transactions worth 0.000001 SUI
  • Threat actors decode the recipient addresses from these microtransactions to reconstruct users’ seed phrases and drain their wallets
  • The extension was uploaded to Chrome Web Store on September 29, 2025 and remained available as of November 13, 2025
  • Warning signs include zero user reviews, grammatical errors in branding, no official website, and a Gmail-linked developer account

A fake cryptocurrency wallet extension on Google’s Chrome Web Store is stealing user seed phrases through an unusual method involving blockchain microtransactions. The extension has appeared high in search results despite containing malicious code.

The extension is named “Safery: Ethereum Wallet.” It markets itself as a secure tool for managing Ethereum-based assets. Blockchain security platform Socket identified the threat in a report published on Tuesday.

The malicious software currently ranks as the fourth search result when users type “Ethereum Wallet” into the Chrome Web Store. It appears just below legitimate wallet extensions like MetaMask, Wombat, and Enkrypt. The extension was first uploaded on September 29, 2025.

The extension works by allowing users to either create new wallets or import existing ones. Both options compromise user security. When a user creates a new wallet, the extension immediately captures the seed phrase.

How the Theft Mechanism Works

The malware uses a unique method to steal credentials without traditional command-and-control servers. It encodes BIP-39 mnemonic seed phrases into synthetic Sui-style blockchain addresses. The extension then sends a microtransaction of 0.000001 SUI to these fake addresses from a wallet controlled by the attackers.

Security researcher Kirill Boychenko from Socket explained the process. The seed phrase leaves the user’s browser hidden inside normal-looking blockchain transactions. Threat actors monitor the Sui blockchain for these tiny transactions.

They can then decode the recipient addresses to reconstruct the original seed phrase. Once they have the seed phrase, they gain complete access to drain all assets from the compromised wallet. The method works whether users create new wallets or import existing ones.

Users who import existing wallets face immediate risk. The moment they enter their seed phrase into the extension, it gets transmitted through the blockchain transaction system. The attackers can access these funds at any time after capturing the credentials.

Warning Signs and Detection

Several red flags indicate the extension’s lack of legitimacy. The extension has zero user reviews on the Chrome Web Store. Its branding contains grammatical mistakes and appears limited in quality.

There is no official website linked to the extension. The developer contact information uses a Gmail account rather than a professional domain. These warning signs should alert users before installing the extension.

Koi Security confirmed the threat in an independent analysis. They verified that the extension monitors the blockchain to decode addresses back to seed phrases. Security experts recommend users only install trusted wallet extensions with verified legitimacy.

Defenders should scan extensions for specific malicious indicators. These include mnemonic encoders, synthetic address generators, and hard-coded seed phrases. Extensions that write to the blockchain during wallet import or creation should be blocked.

Boychenko noted that this technique allows threat actors to switch chains and RPC endpoints easily. Traditional detection methods that rely on domains, URLs, or specific extension IDs will miss this type of attack. Unexpected blockchain RPC calls from browsers should be treated as high-priority security signals.

Users should monitor all wallet transactions consistently. Even transactions involving very small amounts could indicate malicious activity. The extension remained available for download on the Chrome Web Store as of November 13, 2025, with its most recent update occurring on November 12.

The post Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0,01521
$0,01521$0,01521
+%3,82
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fundstrat’s Internal Report Contradicts CIO Tom Lee’s Bold Crypto Forecasts

Fundstrat’s Internal Report Contradicts CIO Tom Lee’s Bold Crypto Forecasts

The post Fundstrat’s Internal Report Contradicts CIO Tom Lee’s Bold Crypto Forecasts appeared on BitcoinEthereumNews.com. Key Points: Fundstrat internal report
Share
BitcoinEthereumNews2025/12/21 13:19
SEC Backs Nasdaq, CBOE, NYSE Push to Simplify Crypto ETF Rules

SEC Backs Nasdaq, CBOE, NYSE Push to Simplify Crypto ETF Rules

The US SEC on Wednesday approved new listing rules for major exchanges, paving the way for a surge of crypto spot exchange-traded funds. On Wednesday, the regulator voted to let Nasdaq, Cboe BZX and NYSE Arca adopt generic listing standards for commodity-based trust shares. The decision clears the final hurdle for asset managers seeking to launch spot ETFs tied to cryptocurrencies beyond Bitcoin and Ether. In July, the SEC outlined how exchanges could bring new products to market under the framework. Asset managers and exchanges must now meet specific criteria, but will no longer need to undergo drawn-out case-by-case reviews. Solana And XRP Funds Seen to Be First In Line Under the new system, the time from filing to launch can shrink to as little as 75 days, compared with up to 240 days or more under the old rules. “This is the crypto ETP framework we’ve been waiting for,” Bloomberg research analyst James Seyffart said on X, predicting a wave of new products in the coming months. The first filings likely to benefit are those tracking Solana and XRP, both of which have sat in limbo for more than a year. SEC Chair Paul Atkins said the approval reflects a commitment to reduce barriers and foster innovation while maintaining investor protections. The move comes under the administration of President Donald Trump, which has signaled strong support for digital assets after years of hesitation during the Biden era. New Standards Replace Lengthy Reviews And Repeated Denials Until now, the commission reviewed each application separately, requiring one filing from the exchange and another from the asset manager. This dual process often dragged on for months and led to repeated denials. Even Bitcoin spot ETFs, finally approved in Jan. 2024, arrived only after years of resistance and a legal battle with Grayscale. According to Bloomberg ETF analyst Eric Balchunas, the streamlined rules could apply to any cryptocurrency with at least six months of futures trading on the Coinbase Derivatives Exchange. That means more than a dozen tokens may now qualify for listing, potentially unleashing a new wave of altcoin ETFs. SEC Clears Grayscale Large Cap Fund Tracking CoinDesk 5 Index The SEC also approved the Grayscale Digital Large Cap Fund, which tracks the CoinDesk 5 Index, including Bitcoin, Ether, XRP, Solana and Cardano. Alongside this, it cleared the launch of options linked to the Cboe Bitcoin US ETF Index and its mini contract, broadening the set of crypto-linked derivatives on regulated US markets. Analysts say the shift shows how far US policy has moved. Where once regulators resisted digital assets, the latest changes show a growing willingness to bring them into the mainstream financial system under established safeguards
Share
CryptoNews2025/09/18 12:40
Bank of Canada cuts rate to 2.5% as tariffs and weak hiring hit economy

Bank of Canada cuts rate to 2.5% as tariffs and weak hiring hit economy

The Bank of Canada lowered its overnight rate to 2.5% on Wednesday, responding to mounting economic damage from US tariffs and a slowdown in hiring. The quarter-point cut was the first since March and met predictions from markets and economists. Governor Tiff Macklem, speaking in Ottawa, said the decision was unanimous. “With a weaker economy […]
Share
Cryptopolitan2025/09/17 23:09