The post Security Researchers Uncovered Dubious “Safery” Crypto Wallet Chrome Store appeared on BitcoinEthereumNews.com. Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.   The extension is called “Safery: Ethereum Wallet” and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets.  However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.   “Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads.  Safety Wallet promo images. Source: Chrome Store Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt.  Chrome store search results. Source: Chrome Store The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user. In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time.  In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.   “When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding:  “By decoding the recipients, the threat… The post Security Researchers Uncovered Dubious “Safery” Crypto Wallet Chrome Store appeared on BitcoinEthereumNews.com. Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.   The extension is called “Safery: Ethereum Wallet” and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets.  However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.   “Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads.  Safety Wallet promo images. Source: Chrome Store Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt.  Chrome store search results. Source: Chrome Store The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user. In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time.  In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.   “When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding:  “By decoding the recipients, the threat…

Security Researchers Uncovered Dubious “Safery” Crypto Wallet Chrome Store

Blockchain security platform Socket has warned of a new malicious crypto wallet extension on Google’s Chrome Web Store that has a unique way of stealing seed phrases to drain user assets.  

The extension is called “Safery: Ethereum Wallet” and claims itself as a “reliable and secure browser extension designed for easy and efficient management” of Ethereum-based assets. 

However, as highlighted in a Tuesday report from Socket, the extension is actually designed to steal seed phrases via a crafty backdoor.  

“Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet,” the report reads. 

Safety Wallet promo images. Source: Chrome Store

Notably, it currently sits as the fourth search result for “Ethereum Wallet” on the Google Chrome store, just a couple of places behind legitimate wallets like MetaMask, Wombat and Enkrypt. 

Chrome store search results. Source: Chrome Store

The extension enables users to create new wallets or import existing ones from elsewhere, thereby establishing two potential security risks for the user.

In the first scenario, the user creates a new wallet in the extension and immediately sends their seed phrase to the bad actor via a tiny Sui-based transaction. As the wallet is compromised from day one, the funds can be stolen at any time. 

In the second scenario, the user imports an existing wallet and enters their seed phrase, handing it over to the scammers behind the extension, who can again view the information via the small transaction.  

“When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor’s mnemonic,” Socket explained, adding: 

How crypto users can avoid scam extensions

While this malicious extension appears high in the search results, there are some clear signs that it lacks legitimacy. 

Related: Scammers posed as Australian police to steal crypto, authorities warn

The extension has zero reviews, very limited branding, grammatical mistakes in some of the branding, no official website, and links to a developer using a Gmail account.

It is important for people to do significant research before they deal with any blockchain platform and tool, be extremely careful with seed phrases, have solid cybersecurity practices, and research well-established alternatives with verified legitimacy. 

Given that this extension also sends microtransactions, it is essential to consistently monitor and identify wallet transactions, as even small transactions could be harmful. 

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack

Source: https://cointelegraph.com/news/malicious-crypto-wallet-google-extension-steals-seed-phrases?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.01862
$0.01862$0.01862
+2.13%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Tokyo’s Metaplanet Launches Miami Subsidiary to Amplify Bitcoin Income

Tokyo’s Metaplanet Launches Miami Subsidiary to Amplify Bitcoin Income

Metaplanet Inc., the Japanese public company known for its bitcoin treasury, is launching a Miami subsidiary to run a dedicated derivatives and income strategy aimed at turning holdings into steady, U.S.-based cash flow. Japanese Bitcoin Treasury Player Metaplanet Opens Miami Outpost The new entity, Metaplanet Income Corp., sits under Metaplanet Holdings, Inc. and is based […]
Share
Coinstats2025/09/18 00:32
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48
“Oversold” Solana Mirroring Previous Bottoms

“Oversold” Solana Mirroring Previous Bottoms

The post “Oversold” Solana Mirroring Previous Bottoms appeared on BitcoinEthereumNews.com. Advertisement &nbsp &nbsp Major cryptocurrency Solana is currently wandering
Share
BitcoinEthereumNews2025/12/24 04:00