Reserved IP Address°C
03-09-2025
BSV
$35.28
Vol 15.8m
-1.3%
BTC
$86136
Vol 16370.55m
0.09%
BCH
$378.85
Vol 205.84m
-0.51%
LTC
$101.41
Vol 520.12m
-3.44%
DOGE
$0.19
Vol 867.35m
-3.58%
Getting your Trinity Audio player ready...

Google has banned 49 extensions for Chrome, after they were found to be harvesting digital currency wallet information from unsuspecting users.

The malicious third-party extensions were removed from the Web Store following the discovery, including extensions impersonating existing digital currency brands, such as Ledger, Trezor and Electrum.

Other extensions found to be stealing digital currency data included Jaxx, MyEtherWallet, MetaMask, Exodus, and KeepKey.

In a post on Medium, Harry Denley, director of security at MyCrypto said the extensions were a way for hackers to gain access to digital currency wallets: “Essentially, the extensions are phishing for secrets — mnemonic phrases, private keys, and keystore files. Once the user has entered them, the extension sends an HTTP POST request to its backend, where the bad actors receive the secrets and empty the accounts.”

“We’ve identified 14 unique C2s (also known as a command & control server that continues to communicate with your compromised system) but by using fingerprinting analysis, we can link specific C2s to each other to conclude which of the phishing kits have the same bad actor(s) behind them.”

The extensions have been linked to a single individual or group based in Russia. However, while the extensions were gathering and communicating wallet data, Henley said this was yet to be exploited by the attackers.

“We’ve sent funds to a few addresses and submitted the secrets to the malicious extensions. However, they were not automatically swept,” Denley said.

The fact accounts remain unswept suggests the hacker may be in the process of developing automated processes for stealing digital currency from compromised wallets. At the moment, all those to have used the extensions remain open to theft from their digital currency wallets.

The ban represents only the latest batch of scam browser extensions targeting digital currency wallets. In March, a Chrome extension impersonating Ledger was involved in stealing digital currency worth over $2.5 million.

The individual or group behind the latest banned extensions remains unconfirmed. With the perpetrator still undetected, it is expected that more malicious extensions and thefts could soon follow. 

Recommended for you

Building a solid ecosystem: Babbage to host BSV Hackathon in Texas
The US$55,000 prize money is up for grabs at the inaugural BSV Hackathon in Austin, Texas, which Babbage will host...
March 3, 2025
GPT-4.5 is not the AGI moment OpenAI teased
While he previously called for lower expectations over GPT-4.5, Sam Altman was lured into dubbing it the closest step to...
March 3, 2025
Advertisement
Advertisement
Advertisement