Socket Finds 19 Chrome and Edge Extensions Draining Crypto Wallets

Socket, an application-security company, said on Aug. 27 it had identified 19 malicious browser extensions, 18 in the Chrome Web Store and one in the Microsoft Edge Add-ons store, that drain cryptocurrency wallets and steal login credentials.
The malicious versions were published within the past six months, researcher Karlo Zanki wrote in Socket's post. Fourteen of the extensions were created by the operators and five were bought from legitimate authors, according to the post. Each followed the same pattern: "The first version implements the advertised functionality and is clean of malware," Socket wrote, with the malicious behavior introduced in a later update.
The largest was "Enable Right Click & Copy — Smart Unlock + OCR," built by PreppHint and later acquired by the threat actor, Socket said. It had around 70,000 users when the malicious functionality was introduced, and the Edge version carries around 10,000, which Socket counts as a potential impact surface of 80,000 users. Socket wrote that this "does not necessarily mean all of the users had the malicious version installed."
At the time of publication, Socket said, the Chrome listing had been identified as malicious and removed from the Chrome Web Store, while the Edge version was "still active and serving malware." Socket said it reported the finding to the Edge extension store, and that a new Edge version was published on Aug. 14, 2026, using a different control server.
Socket said it observed 16 malicious modules delivered to that extension, including a multi-chain wallet drainer, pages imitating Ledger and Trezor recovery wizards to capture wallet recovery phrases, modules that read balances and session data from logged-in exchange accounts — among them Coinbase, Binance and Kraken — a form grabber, and fake browser-update lures. The list "is not exhaustive nor final," the company wrote.
Socket said it tracks the campaign as "Superior," after tags in the names of the malicious modules, and links it to activity DomainTools reported dating to February 2024.
