According to Deep Tide TechFlow news, on November 14, as disclosed by the GoPlus Chinese community, a malicious Chrome extension named “Safery: Ethereum Wallet” has been discovered that is stealing user assets. This extension was released on November 12, 2024, disguised as a simple and secure Ethereum Wallet, but contains a backdoor.
The attack method has a high degree of concealment: the malicious plugin encodes the user's mnemonic phrase into a Sui address and broadcasts microtransactions through a Sui Wallet controlled by the attacker to steal the mnemonic phrase. The attacker's email is kifagusertyna@gmail[.]com.
The malicious extension has not yet been removed from the Chrome Web Store.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
GoPlus: Malicious Chrome extension "Safery: Ethereum Wallet" disguises as an ETH Wallet to steal users' mnemonic phrase.
According to Deep Tide TechFlow news, on November 14, as disclosed by the GoPlus Chinese community, a malicious Chrome extension named “Safery: Ethereum Wallet” has been discovered that is stealing user assets. This extension was released on November 12, 2024, disguised as a simple and secure Ethereum Wallet, but contains a backdoor.
The attack method has a high degree of concealment: the malicious plugin encodes the user's mnemonic phrase into a Sui address and broadcasts microtransactions through a Sui Wallet controlled by the attacker to steal the mnemonic phrase. The attacker's email is kifagusertyna@gmail[.]com.
The malicious extension has not yet been removed from the Chrome Web Store.