Malicious Chrome and Edge Extensions Drained Crypto Wallets From 80,000 Users

A six-month campaign using 19 malicious Chrome and Edge extensions drained crypto wallets across EVM, Solana, and Tron chains. One extension had 70,000 Chrome users before removal.
Cybersecurity firm Socket uncovered a campaign built around 19 malicious browser extensions, 18 targeting Google Chrome and one targeting Microsoft Edge. The operation has been active for roughly six months, with signs it probably kicked off around February 2024.
Socket's researchers found that 14 of the 19 extensions were built from scratch by the threat actors. The other five started as legitimate extensions that developers had already published, acquired and then weaponized.
The Biggest Extension Had 70,000 Users
Socket flagged "Enable Right Click & Copy. Smart Unlock + OCR" as the most dangerous extension in the campaign. Chrome pulled it from the Web Store. The Microsoft Edge version of the same extension, roughly 10,000 users, remains active as of the time Socket published its findings.
The technical setup is multi-chain. Socket's researchers found a cryptocurrency wallet drainer embedded in the extensions targeting EVM-compatible wallets, Solana wallets, and Tron wallets. The malware can manipulate legitimate "Connect Wallet" and "Swap" buttons users click on DeFi platforms every day, quietly redirecting the transaction flow toward attacker-controlled processes.
Hardware wallet users are not safe either. The campaign includes fake recovery and update pages designed to look like official Ledger and Trezor interfaces. The goal is straightforward: get the user to enter their seed phrase.
The extensions include modules built to harvest authenticated session data and account credentials from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. If a user is logged into any of those while running a compromised extension, their session data is at risk.
Stripping Browser Defenses
Socket said these extensions can strip Content Security Policy headers from websites, tearing down one of the core browser-level defenses against malicious scripts. Scripts that would normally get blocked can now run, creating an open door for further exploitation.
The campaign also targets Facebook and LinkedIn accounts. Modules designed to compromise those accounts are baked into the same extensions.
There is also a ClickFix-style component. Fake browser-update pages that mimic legitimate Chrome or Edge update prompts push users to download additional malware.
Browsing history is also being harvested. That data can be used to build profiles, identify which crypto platforms a user frequents, and tailor further attacks.
Socket's advice: regularly audit browser extensions. Remove anything that looks suspicious or that you don't actively use. For hardware wallet users, seed phrases should never be entered into any browser-based interface. Official recovery processes for those devices do not happen in a Chrome tab.
The Chrome version of "Enable Right Click & Copy. Smart Unlock + OCR" is down. The Edge version, with its 10,000 users, is still up.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.