Malicious Chrome Wallet Steals Seed Phrases via Sui Blockchain

Malicious Chrome Wallet Steals Seed Phrases via Sui Blockchain

View Crypto Cold Wallets Reviews
Multi-Factor Authentication Tools Reviews

A sophisticated malicious Chrome extension named “Safery: Ethereum Wallet” recently posed a significant threat, briefly ranking as the fourth result for “Ethereum wallet” on the Chrome Web Store. Unlike typical phishing scams, Safery didn’t impersonate existing brands; instead, it created a new, polished identity, complete with a clean icon, generic security-adjacent name, and a flood of five-star reviews. This allowed it to bypass immediate red flags like broken grammar or odd permissions, making it appear legitimate to unsuspecting users.

TheThe core danger lay in its purpose-built attack to steal seed phrases. Upon entering a seed phrase, the extension silently fragmented it and encoded these pieces into micro-transactions on the Sui blockchain. These minuscule SUI token transfers to attacker-controlled addresses, often containing seed fragments in memo fields or obfuscated addresses, appeared as normal blockchain activity. This innovative method bypassed traditional security measures, as there were no suspicious outbound requests to malicious servers or exfiltration over HTTP/WebSockets that antivirus software or browsers might flag. The Sui blockchain effectively served as a covert communications channel, allowing attackers to reconstruct seed phrases and sweep victim wallets without further device interaction.

Bundle Banner Small — AI Tools Integration
Limited Time
🔥 Lifetime Deal Bundle

3 SaaS Tools for the Price of 2

"It's not SaaS of the Day — It's Must Have SaaS"

🔗 Auto Backlinks Builder
📰 AI Content Aggregator
🖼️ AI Post Image Generator
1 Site
$98
Lifetime
3 Sites
$198
Lifetime
10 Sites
$498
Lifetime
50 Sites
$1398
Lifetime
Get the Bundle — Save 33% →

One-time payment · No subscription · All 3 tools included · Limited time offer

Up to 500 free bonus tokens on every new account

Security firm Socket analyzed Safery, highlighting how Chrome’s ranking algorithm, which prioritizes keyword match, install count, and review velocity, enabled its rise. Despite lacking manual Google review, Safery exploited these factors with a blitz of botted reviews and a fresh upload. Users were advised to immediately uninstall the extension, revoke token approvals, sweep assets to new wallets, and monitor addresses. This incident underscores the critical blind spot browser extensions represent in crypto security.

The “Safery” case prompts a re-evaluation of trust in crypto UX. Recommendations include stronger Chrome heuristics to flag UI elements prompting for seed phrases, requiring publisher attestation, and tighter inspection of wallet-related permissions. For users, vigilance is key: always verify publisher history, check for real website links and GitHub repositories, and scrutinize review patterns and requested permissions before installing any crypto extension. The accessibility of browser wallets comes with heightened exposure, turning them from a vault into an “open port” if not handled with extreme caution.

(Source: https://cryptoslate.com/security-reality-check-top-ranked-chrome-wallet-that-steals-your-seedphrase/)

Multi-Factor Authentication Tools Reviews

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *