• bitcoinBitcoin (BTC) $ 90,239.00
  • ethereumEthereum (ETH) $ 3,085.58
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 883.96
  • xrpXRP (XRP) $ 2.02
  • usd-coinUSDC (USDC) $ 0.999822
  • solanaWrapped SOL (SOL) $ 132.62
  • staked-etherLido Staked Ether (STETH) $ 3,084.82
  • tronTRON (TRX) $ 0.274665
  • dogecoinDogecoin (DOGE) $ 0.137372
  • cardanoCardano (ADA) $ 0.410443
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • whitebitWhiteBIT Coin (WBT) $ 60.50
  • wrapped-stethWrapped stETH (WSTETH) $ 3,768.60
  • bitcoin-cashBitcoin Cash (BCH) $ 583.35
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 89,871.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,347.19
  • usdsUSDS (USDS) $ 0.999806
  • chainlinkChainlink (LINK) $ 13.68
  • wrapped-eethWrapped eETH (WEETH) $ 3,341.51
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.53
  • wethWETH (WETH) $ 3,084.55
  • stellarStellar (XLM) $ 0.238858
  • hyperliquidHyperliquid (HYPE) $ 28.43
  • zcashZcash (ZEC) $ 461.22
  • moneroMonero (XMR) $ 404.82
  • ethena-usdeEthena USDe (USDE) $ 0.999303
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 90,227.00
  • litecoinLitecoin (LTC) $ 82.10
  • suiSui (SUI) $ 1.58
  • avalanche-2Avalanche (AVAX) $ 13.18
  • hedera-hashgraphHedera (HBAR) $ 0.125301
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • susdssUSDS (SUSDS) $ 1.07
  • usdt0USDT0 (USDT0) $ 1.00
  • daiDai (DAI) $ 0.999669
  • mantleMantle (MNT) $ 1.25
  • the-open-networkToncoin (TON) $ 1.61
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.144239
  • paypal-usdPayPal USD (PYUSD) $ 0.999908
  • crypto-com-chainCronos (CRO) $ 0.100199
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • uniswapUniswap (UNI) $ 5.41
  • polkadotPolkadot (DOT) $ 2.02
  • aaveAave (AAVE) $ 194.27
  • bittensorBittensor (TAO) $ 295.79
  • memecoreMemeCore (M) $ 1.62
  • usd1-wlfiUSD1 (USD1) $ 0.999196
  • canton-networkCanton (CC) $ 0.070540
  • rainRain (RAIN) $ 0.007411
  • bitget-tokenBitget Token (BGB) $ 3.60
  • okbOKB (OKB) $ 115.08
  • tether-goldTether Gold (XAUT) $ 4,295.54
  • falcon-financeFalcon USD (USDF) $ 0.998268
  • nearNEAR Protocol (NEAR) $ 1.64
  • ethereum-classicEthereum Classic (ETC) $ 12.99
  • aster-2Aster (ASTER) $ 0.954661
  • ethenaEthena (ENA) $ 0.248661
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,086.03
  • jito-staked-solJito Staked SOL (JITOSOL) $ 165.51
  • pepePepe (PEPE) $ 0.000004
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • internet-computerInternet Computer (ICP) $ 3.24
  • pi-networkPi Network (PI) $ 0.207757
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.65
  • hash-2Provenance Blockchain (HASH) $ 0.031350
  • pump-funPump.fun (PUMP) $ 0.002772
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pax-goldPAX Gold (PAXG) $ 4,311.58
  • ondo-financeOndo (ONDO) $ 0.461398
  • worldcoin-wldWorldcoin (WLD) $ 0.582432
  • global-dollarGlobal Dollar (USDG) $ 0.999738
  • kucoin-sharesKuCoin (KCS) $ 10.60
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • skySky (SKY) $ 0.057666
  • bfusdBFUSD (BFUSD) $ 0.999241
  • ripple-usdRipple USD (RLUSD) $ 0.999599
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,544.22
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999890
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.119656
  • kaspaKaspa (KAS) $ 0.046125
  • aptosAptos (APT) $ 1.64
  • gatechain-tokenGate (GT) $ 10.32
  • quant-networkQuant (QNT) $ 82.34
  • wbnbWrapped BNB (WBNB) $ 883.69
  • arbitrumArbitrum (ARB) $ 0.206226
  • binance-staked-solBinance Staked SOL (BNSOL) $ 144.23
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,269.98
  • official-trumpOfficial Trump (TRUMP) $ 5.61
  • algorandAlgorand (ALGO) $ 0.121803
  • ignition-fbtcFunction FBTC (FBTC) $ 90,684.00
  • cosmosCosmos Hub (ATOM) $ 2.16
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,304.49
  • vechainVeChain (VET) $ 0.011679
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,176.00
  • flare-networksFlare (FLR) $ 0.012375
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 89,943.00
  • nexoNEXO (NEXO) $ 0.977933
  • filecoinFilecoin (FIL) $ 1.34
  • xdce-crowd-saleXDC Network (XDC) $ 0.049119
  • midnight-3Midnight (NIGHT) $ 0.050820
  • usdtbUSDtb (USDTB) $ 0.998364
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.92
  • sei-networkSei (SEI) $ 0.129590
  • ousgOUSG (OUSG) $ 113.62
  • render-tokenRender (RENDER) $ 1.55
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 28.62
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999762
  • bonkBonk (BONK) $ 0.000009
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.21
  • usddUSDD (USDD) $ 0.999996
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,072.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,337.97
  • wrapped-flareWrapped Flare (WFLR) $ 0.012381
  • clbtcclBTC (CLBTC) $ 90,545.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998706
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010852
  • ultimaUltima (ULTIMA) $ 6,786.37
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999806
  • beldexBeldex (BDX) $ 0.088191
  • usdaiUSDai (USDAI) $ 1.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,288.11
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 153.40
  • jupiter-exchange-solanaJupiter (JUP) $ 0.203428
  • story-2Story (IP) $ 1.88
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999975
  • morphoMorpho (MORPHO) $ 1.15
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,085.33
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.238187
  • optimismOptimism (OP) $ 0.308568
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,195.03
  • myx-financeMYX Finance (MYX) $ 3.08
  • dashDash (DASH) $ 46.19
  • curve-dao-tokenCurve DAO (CRV) $ 0.395699
  • aerodrome-financeAerodrome Finance (AERO) $ 0.606876
  • usual-usdUsual USD (USD0) $ 0.996079
  • tbtctBTC (TBTC) $ 89,895.00
  • spx6900SPX6900 (SPX) $ 0.580953
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,084.51
  • injective-protocolInjective (INJ) $ 5.36
  • tezosTezos (XTZ) $ 0.497676
  • lido-daoLido DAO (LDO) $ 0.589192
  • bridged-wrapped-ether-pundi-aifx-omnilayerBridged Wrapped Ether (Pundi AIFX Omnilayer) (WETH) $ 35,382,014.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.799929
  • blockstackStacks (STX) $ 0.287561
  • starknetStarknet (STRK) $ 0.105030
  • gtethGTETH (GTETH) $ 3,084.88
  • true-usdTrueUSD (TUSD) $ 0.995880
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • celestiaCelestia (TIA) $ 0.574317
  • ether-fiEther.fi (ETHFI) $ 0.800769
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • newton-projectAB (AB) $ 0.005252
  • msolMarinade Staked SOL (MSOL) $ 178.37
  • telcoinTelcoin (TEL) $ 0.004891
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.230009
  • stader-ethxStader ETHx (ETHX) $ 3,320.60
  • ghoGHO (GHO) $ 0.999639
  • flokiFLOKI (FLOKI) $ 0.000046
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,256.96
  • kaiaKaia (KAIA) $ 0.074588
  • the-graphThe Graph (GRT) $ 0.040848
  • merlin-chainMerlin Chain (MERL) $ 0.410481
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.991542
  • basic-attention-tokenBasic Attention (BAT) $ 0.284153
  • iotaIOTA (IOTA) $ 0.100198
  • doublezeroDoubleZero (2Z) $ 0.120606
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.84
  • swethSwell Ethereum (SWETH) $ 3,391.95
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • usdbUSDB (USDB) $ 1.00
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.968021
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • sbtc-2sBTC (SBTC) $ 90,551.00
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,434.81
  • bitcoin-svBitcoin SV (BSV) $ 19.71
  • sun-tokenSun Token (SUN) $ 0.020385
  • dogwifcoindogwifhat (WIF) $ 0.390062
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • justJUST (JST) $ 0.038267
  • fartcoinFartcoin (FARTCOIN) $ 0.370613
  • pyth-networkPyth Network (PYTH) $ 0.064317
  • conflux-tokenConflux (CFX) $ 0.071031
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 90,240.00
  • olympusOlympus (OHM) $ 22.12
  • pendlePendle (PENDLE) $ 2.20
  • apenftAINFT (NFT) $ 0.00000036
  • crvusdcrvUSD (CRVUSD) $ 0.998551
  • decredDecred (DCR) $ 20.57
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.137382
  • the-sandboxThe Sandbox (SAND) $ 0.132514
  • theta-tokenTheta Network (THETA) $ 0.345869
  • chilizChiliz (CHZ) $ 0.034025
  • sonic-3Sonic (S) $ 0.090551
  • heliumHelium (HNT) $ 1.83

Chrome Web Store’s No. 4 crypto wallet can steal user seed phrases

0 22

Chrome Web Store’s No. 4 crypto wallet can steal user seed phrases

Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.

The extension is called “Safery: Ethereum Wallet”and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets.

However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.

“Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads.

Chrome Web Store’s No. 4 crypto wallet can steal user seed phrases

Safety Wallet promo images. Source: Chrome Store

Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt.

Chrome Web Store’s No. 4 crypto wallet can steal user seed phrases

Chrome store search results. Source: Chrome Store

The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user.

In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time.

In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.

“When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding:

“By decoding the recipients, the threat actor reconstructs the original seed phrase and can drain affected assets. The mnemonic leaves the browser concealed inside normal-looking blockchain transactions.”

How crypto users can avoid scam extensions

While this malicious extension appears high in the search results, there are some clear signs that it lacks legitimacy.

Related: Scammers posed as Australian police to steal crypto, authorities warn

The extension has zero reviews, very limited branding, grammatical mistakes in some of the branding, no official website, and links to a developer using a Gmail account.

It is important for people to do significant research before they deal with any blockchain platform and tool, be extremely careful with seed phrases, have solid cybersecurity practices, and research well-established alternatives with verified legitimacy.

Given that this extension also sends microtransactions, it is essential to consistently monitor and identify wallet transactions, as even small transactions could be harmful.

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack

Source

Leave A Reply

Your email address will not be published.