Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data
Fake Chrome and Firefox extensions for crypto traders secretly steal your login tokens and wallet keys. Attackers repackaged real trading tools to trick users into installing them, then sent your private session data to their own servers.
- Report priority
- Medium
- Targets
- Finance
How it works
- Attackers took real crypto-trading browser extensions and added hidden code to them.
- When you installed one of these fake extensions, it ran in your browser every time you visited Axiom Trade or Padre.
- The hidden code copied your login tokens, wallet keys, and other private session data from your browser's memory.
- It then sent that data to the attackers' own servers using a trick that avoids browser security blocks.
- This lets them steal your crypto accounts and trade on your behalf.
What to do
If you installed a Chrome or Firefox extension called J7Tracker, VREO, Orbit Tracker, or any other crypto-trading tool from the last few months, check if it was installed from a trusted source. Run chrome://extensions in Chrome or about:addons in Firefox, then look for any unfamiliar extensions related to crypto trading. If you see one you don't recognize, remove it immediately. If you used Axiom Trade or Padre and installed any crypto-related extensions recently, assume your login and wallet data may have been stolen.
Remove any suspicious crypto-trading extensions from Chrome or Firefox right away. Change your passwords for Axiom Trade, Padre, and any crypto wallets you use. Enable two-factor authentication on all trading accounts. Monitor your accounts for unauthorized transactions. If you suspect your wallet was compromised, contact the support team of the affected platform immediately.
Technical details
Affected software: Finance
Attackers repackaged real crypto-trading extensions like J7Tracker and VREO, then uploaded them to Chrome and Firefox extension stores. When users installed these fake versions, the hidden code ran in their browser sessions on Axiom Trade and Padre. The stolen data included login tokens, wallet keys, and trading history, which were sent to attacker-controlled servers via a hidden web request.
Six malicious Chrome and Firefox extensions, J7Tracker, VREO, Orbit Tracker, and others, target cryptocurrency traders by stealing authenticated session tokens and wallet data from platforms like Axiom Trade and Padre. The extensions harvest localStorage, IndexedDB, and API responses containing Firebase tokens and wallet keys, then exfiltrate the data to attacker-controlled Vercel deployments via Base64-encoded browser navigation to bypass CORS restrictions. This allows attackers to hijack user sessions and steal cryptocurrency. The campaign specifically targets active trading communities, including Axiom Trade, which processes over $15 billion in volume across 650,000 wallets.