19 fake crypto extensions stole wallets

Published August 30, 2026

Fake crypto wallet extensions for Microsoft Edge and Chrome secretly stole users' wallet passwords and other private data. Attackers took over real extensions and pushed harmful updates to thousands of users.

Report priority
Medium
Involves
Microsoft Edge

What is known

Attackers took over legitimate crypto wallet extensions, then pushed harmful updates that secretly stole users' wallet passwords and other private data.

What to do

Check if you have any of the 19 fake crypto wallet extensions installed in Microsoft Edge or Chrome by reviewing your installed extensions list.

Remove all 19 fake extensions immediately from Microsoft Edge or Chrome, then update your browser to the latest version to prevent further risks.

Reported details

A user installs a crypto wallet extension that promises to help track prices or unlock wallets. Later, the extension quietly updates itself with malicious code that steals their wallet password and other private data. The attacker then drains the user's crypto wallet or sells the stolen data.

Nineteen browser extensions, 18 for Chrome and one for Microsoft Edge, were compromised in a malware campaign targeting cryptocurrency wallet theft. The extensions initially appeared legitimate, offering features like search assistance, price tracking, and clipboard unlocking, but later versions silently introduced malicious code. Researchers at Socket.dev tracked the operation as "Superior," noting that attackers either created new extensions or acquired established ones with existing users, then pushed harmful updates via routine automatic mechanisms.

The most widely used extension, Enable Right Click & Copy, Smart Unlock + OCR, potentially affected 80,000 users before Google removed its Chrome version, though the Edge counterpart remained active at the time of discovery. The malware framework allows attackers to dynamically download and execute payloads, enabling wallet secret theft, credential harvesting, session data exfiltration, and browsing history collection. The extensions establish encrypted WebSocket connections to attacker-controlled servers, which can rotate to avoid detection and use separate endpoints for stolen data.

The campaign highlights how seemingly trustworthy extensions can be weaponized after acquisition, leaving users unaware of the shift in ownership and risk.