TLDR A malicious Chrome extension called “Safery: Ethereum Wallet” ranks fourth in Chrome Web Store searches for Ethereum wallets The extension steals seed phrases by encoding them into fake Sui blockchain addresses and sending tiny transactions worth 0.000001 SUI Threat actors decode the recipient addresses from these microtransactions to reconstruct users’ seed phrases and drain [...] The post Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions appeared first on CoinCentral.TLDR A malicious Chrome extension called “Safery: Ethereum Wallet” ranks fourth in Chrome Web Store searches for Ethereum wallets The extension steals seed phrases by encoding them into fake Sui blockchain addresses and sending tiny transactions worth 0.000001 SUI Threat actors decode the recipient addresses from these microtransactions to reconstruct users’ seed phrases and drain [...] The post Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions appeared first on CoinCentral.

Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions

TLDR

  • A malicious Chrome extension called “Safery: Ethereum Wallet” ranks fourth in Chrome Web Store searches for Ethereum wallets
  • The extension steals seed phrases by encoding them into fake Sui blockchain addresses and sending tiny transactions worth 0.000001 SUI
  • Threat actors decode the recipient addresses from these microtransactions to reconstruct users’ seed phrases and drain their wallets
  • The extension was uploaded to Chrome Web Store on September 29, 2025 and remained available as of November 13, 2025
  • Warning signs include zero user reviews, grammatical errors in branding, no official website, and a Gmail-linked developer account

A fake cryptocurrency wallet extension on Google’s Chrome Web Store is stealing user seed phrases through an unusual method involving blockchain microtransactions. The extension has appeared high in search results despite containing malicious code.

The extension is named “Safery: Ethereum Wallet.” It markets itself as a secure tool for managing Ethereum-based assets. Blockchain security platform Socket identified the threat in a report published on Tuesday.

The malicious software currently ranks as the fourth search result when users type “Ethereum Wallet” into the Chrome Web Store. It appears just below legitimate wallet extensions like MetaMask, Wombat, and Enkrypt. The extension was first uploaded on September 29, 2025.

The extension works by allowing users to either create new wallets or import existing ones. Both options compromise user security. When a user creates a new wallet, the extension immediately captures the seed phrase.

How the Theft Mechanism Works

The malware uses a unique method to steal credentials without traditional command-and-control servers. It encodes BIP-39 mnemonic seed phrases into synthetic Sui-style blockchain addresses. The extension then sends a microtransaction of 0.000001 SUI to these fake addresses from a wallet controlled by the attackers.

Security researcher Kirill Boychenko from Socket explained the process. The seed phrase leaves the user’s browser hidden inside normal-looking blockchain transactions. Threat actors monitor the Sui blockchain for these tiny transactions.

They can then decode the recipient addresses to reconstruct the original seed phrase. Once they have the seed phrase, they gain complete access to drain all assets from the compromised wallet. The method works whether users create new wallets or import existing ones.

Users who import existing wallets face immediate risk. The moment they enter their seed phrase into the extension, it gets transmitted through the blockchain transaction system. The attackers can access these funds at any time after capturing the credentials.

Warning Signs and Detection

Several red flags indicate the extension’s lack of legitimacy. The extension has zero user reviews on the Chrome Web Store. Its branding contains grammatical mistakes and appears limited in quality.

There is no official website linked to the extension. The developer contact information uses a Gmail account rather than a professional domain. These warning signs should alert users before installing the extension.

Koi Security confirmed the threat in an independent analysis. They verified that the extension monitors the blockchain to decode addresses back to seed phrases. Security experts recommend users only install trusted wallet extensions with verified legitimacy.

Defenders should scan extensions for specific malicious indicators. These include mnemonic encoders, synthetic address generators, and hard-coded seed phrases. Extensions that write to the blockchain during wallet import or creation should be blocked.

Boychenko noted that this technique allows threat actors to switch chains and RPC endpoints easily. Traditional detection methods that rely on domains, URLs, or specific extension IDs will miss this type of attack. Unexpected blockchain RPC calls from browsers should be treated as high-priority security signals.

Users should monitor all wallet transactions consistently. Even transactions involving very small amounts could indicate malicious activity. The extension remained available for download on the Chrome Web Store as of November 13, 2025, with its most recent update occurring on November 12.

The post Fake Ethereum Wallet Extension Steals Seed Phrases Through Blockchain Transactions appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.01383
$0.01383$0.01383
+1.02%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Unleashing A New Era Of Seller Empowerment

Unleashing A New Era Of Seller Empowerment

The post Unleashing A New Era Of Seller Empowerment appeared on BitcoinEthereumNews.com. Amazon AI Agent: Unleashing A New Era Of Seller Empowerment Skip to content Home AI News Amazon AI Agent: Unleashing a New Era of Seller Empowerment Source: https://bitcoinworld.co.in/amazon-ai-seller-tools/
Share
BitcoinEthereumNews2025/09/18 00:10
Yei Finance's cross-chain product Clovis opens its fourth round of pre-deposits, and TGE will be launched soon.

Yei Finance's cross-chain product Clovis opens its fourth round of pre-deposits, and TGE will be launched soon.

PANews reported on September 18th that Clovis, a cross-chain protocol under Yei Finance, officially launched its fourth pre-deposit campaign at 9:00 PM on the evening of September 18th, lasting 24 hours. This campaign, for the first time, adopted an "unlimited" deposit mechanism, aiming to expand user participation and inject market momentum into the upcoming TGE. The event prioritizes the community: the first two hours are dedicated to Yeiliens NFT holders. Users who deposit the first $1.5 million will receive Clovis Points (Season 1) as a reward, which can be used for future ecosystem governance and equity distribution. Clovis continues to optimize cross-chain asset efficiency through its multi-chain infrastructure, and this pre-deposit is considered an important step in the project's ecosystem preparation prior to the TGE.
Share
PANews2025/09/18 21:10
CME Group to launch Solana and XRP futures options in October

CME Group to launch Solana and XRP futures options in October

The post CME Group to launch Solana and XRP futures options in October appeared on BitcoinEthereumNews.com. CME Group is preparing to launch options on SOL and XRP futures next month, giving traders new ways to manage exposure to the two assets.  The contracts are set to go live on October 13, pending regulatory approval, and will come in both standard and micro sizes with expiries offered daily, monthly and quarterly. The new listings mark a major step for CME, which first brought bitcoin futures to market in 2017 and added ether contracts in 2021. Solana and XRP futures have quickly gained traction since their debut earlier this year. CME says more than 540,000 Solana contracts (worth about $22.3 billion), and 370,000 XRP contracts (worth $16.2 billion), have already been traded. Both products hit record trading activity and open interest in August. Market makers including Cumberland and FalconX plan to support the new contracts, arguing that institutional investors want hedging tools beyond bitcoin and ether. CME’s move also highlights the growing demand for regulated ways to access a broader set of digital assets. The launch, which still needs the green light from regulators, follows the end of XRP’s years-long legal fight with the US Securities and Exchange Commission. A federal court ruling in 2023 found that institutional sales of XRP violated securities laws, but programmatic exchange sales did not. The case officially closed in August 2025 after Ripple agreed to pay a $125 million fine, removing one of the biggest uncertainties hanging over the token. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/cme-group-solana-xrp-futures
Share
BitcoinEthereumNews2025/09/17 23:55