Need help? Support
BITCOIN
Tether Dominance USDT.D

Which extension targets ETH wallets?

Published 358 words 2 min read

TLDR

The malicious Chrome extension is Safery: Ethereum Wallet, designed to steal seed phrases from Ethereum (ETH) users via a hidden backdoor per a recent report.

  1. It encodes seed phrases into synthetic Sui-style addresses and leaks them via micro SUI transactions per the report.
  2. It was still listed on the Chrome Web Store at the time of the alert, raising urgency for checks, per the report.
  3. GoPlus issued a security alert and blacklisted its link, identifying Safery: Wallet as the threat per the alert.

Deep Dive

1. Attack Method

The extension implants a backdoor that captures the BIP-39 mnemonic (seed phrase), encodes it into Sui-style addresses, and triggers micro-transactions of SUI to those addresses using an attacker-controlled mnemonic. Decoding the recipients lets the attacker reconstruct the original seed phrase and drain assets per the report.

  • Two scenarios are enabled: compromising newly created wallets in the extension or stealing imported seed phrases per the report.
What this means

Even harmless-looking micro-transactions can be a signal of seed exfiltration, so monitoring unusual activity matters.

2. Status And Scope

The extension ranked among top Ethereum Wallet search results and was still live on the Chrome Web Store at the time of the alert, increasing exposure risk for casual users per the report.

  • GoPlus flagged Safery: Wallet, reported it to Chrome, and blacklisted the download link, yet availability persisted per the alert.
What this means

Listing presence is not proof of safety. Rely on official wallet sites and verified publisher pages instead of store search alone.

3. Practical Guardrails

The malicious listing showed red flags: zero reviews, thin branding, grammar issues, no official site, and a Gmail developer contact per the report.

  • Verify any wallet extension against the projects official site, and treat unexplained micro-transactions or unfamiliar addresses as a potential compromise per the report.
What this means

A simple pre-check (publisher verification and official links) can prevent seed loss without operational complexity.

Conclusion

Safery: Ethereum Wallet is the identified malicious Chrome extension targeting ETH users, using covert micro-transactions to exfiltrate seed phrases per the linked report. The alert underscores that store presence is not a safety guarantee, so verify extensions via official wallet sites and treat suspicious micro-transactions as a potential compromise.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top