19 Malicious Chrome & Edge Extensions Found Stealing Crypto Wallets
Cybersecurity researchers at Socket have uncovered a cluster of 19 malicious browser extensions—18 targeting Google Chrome and one targeting Microsoft Edge—that have been actively stealing cryptocurrency wallet secrets from unsuspecting users over the past six months. The extensions share notable similarities in code structure and tradecraft, and according to Socket researcher Karlo Zanki, the campaign—tracked under the name "Superior"—may have been operational since February 2024, making it a sustained and well-organized supply chain threat.
The threat actors employed a deceptive two-phase approach. Initially, they either acquired legitimate extensions from their original developers or published clean, fully functional versions to build user trust and accumulate downloads. Once a sufficient user base was established, the operators pushed malicious updates containing wallet-stealing and crypto-draining code. Of the 19 extensions identified, 14 were created by the attackers, while five were purchased from previous owners. Notable examples include "QuickLens - Search Screen with Google Lens," "Crypto Price Badge: Quick Glance," "Blockfolio: Address Monitor," and "Meta & Facebook Ad Library Spy."
Several of the malicious extensions had been previously flagged. "QuickLens" was identified by both Annex Security and monxresearch-sec earlier this year for distributing malware, injecting arbitrary code, and harvesting sensitive data. DomainTools Investigations also documented elements of the campaign in May 2025, suggesting the operation's scope is far broader than initially understood. The full list of compromised extensions has been published by Socket, enabling security teams to audit their environments and alert affected users.
This campaign underscores the persistent risks of the browser extension supply chain, where trusted tools can silently turn malicious after gaining a foothold. Users who have installed any of the flagged extensions should immediately remove them, revoke all connected wallet permissions, and rotate their credentials. A password checker can help verify whether any stored credentials have been exposed, while a email breach checker is useful for identifying compromised accounts. For ongoing protection, running a browser fingerprint test can reveal what trackers and extensions may be exposing about your device and online identity.