TLDR
The malicious Chrome extension is Safery: Ethereum Wallet, designed to steal seed phrases from Ethereum (ETH) users via a hidden backdoor per a recent report.
- It encodes seed phrases into synthetic Sui-style addresses and leaks them via micro SUI transactions per the report.
- It was still listed on the Chrome Web Store at the time of the alert, raising urgency for checks, per the report.
- GoPlus issued a security alert and blacklisted its link, identifying Safery: Wallet as the threat per the alert.
Deep Dive
1. Attack Method
The extension implants a backdoor that captures the BIP-39 mnemonic (seed phrase), encodes it into Sui-style addresses, and triggers micro-transactions of SUI to those addresses using an attacker-controlled mnemonic. Decoding the recipients lets the attacker reconstruct the original seed phrase and drain assets per the report.
- Two scenarios are enabled: compromising newly created wallets in the extension or stealing imported seed phrases per the report.
Even harmless-looking micro-transactions can be a signal of seed exfiltration, so monitoring unusual activity matters.
2. Status And Scope
The extension ranked among top Ethereum Wallet search results and was still live on the Chrome Web Store at the time of the alert, increasing exposure risk for casual users per the report.
- GoPlus flagged Safery: Wallet, reported it to Chrome, and blacklisted the download link, yet availability persisted per the alert.
Listing presence is not proof of safety. Rely on official wallet sites and verified publisher pages instead of store search alone.
3. Practical Guardrails
The malicious listing showed red flags: zero reviews, thin branding, grammar issues, no official site, and a Gmail developer contact per the report.
- Verify any wallet extension against the projects official site, and treat unexplained micro-transactions or unfamiliar addresses as a potential compromise per the report.
A simple pre-check (publisher verification and official links) can prevent seed loss without operational complexity.
Conclusion
Safery: Ethereum Wallet is the identified malicious Chrome extension targeting ETH users, using covert micro-transactions to exfiltrate seed phrases per the linked report. The alert underscores that store presence is not a safety guarantee, so verify extensions via official wallet sites and treat suspicious micro-transactions as a potential compromise.
