Bitcoin Forum
June 19, 2024, 11:47:39 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: 49 Cryptocurrency Wallet Browser Extensions Found Stealing Private keys  (Read 153 times)
SUMBI99 (OP)
Jr. Member
*
Offline Offline

Activity: 79
Merit: 3


View Profile WWW
April 15, 2020, 09:49:49 PM
Last edit: April 15, 2020, 11:07:14 PM by SUMBI99
 #1

Google has removed 49 cryptocurrency wallet browser extensions after a security researcher discovered they were stealing private keys. These Chrome extensions targeted users of crypto wallets, such as Ledger, Trezor, Jaxx, Electrum, Myetherwallet, Metamask, Exodus, and Keepkey.

Security researcher Harry Denley further revealed that the cryptocurrency wallets targeted by the 49 malicious Chrome browser extensions were Ledger, Trezor, Jaxx, Electrum, Myetherwallet, Metamask, Exodus, and Keepkey. He found that the most attacked wallet was Ledger, targeted by 57% of the malicious browser extensions. The second most targeted wallet was Myetherwallet (22%), followed by Trezor (8%), Electrum (4%), Keepkey (4%), and Jaxx (2%).


Read More On::https://news.bitcoin.com/google-cryptocurrency-wallet-browser/?utm_source=OneSignal%20Push&utm_medium=notification&utm_campaign=Push%20Notifications
aemma
Copper Member
Member
**
Offline Offline

Activity: 966
Merit: 14


View Profile
May 01, 2020, 10:22:35 AM
 #2

The more cryptocurrencies grows the more scammers and hackers keeps looking for ways to steal from people then proving the fact that, crypto is highly valuable (depends on the crypto though) no matter how most people sees it. However, this is a call for concern (49 browser extensions is too much) that we should be extremely careful of the type of browser extensions we install, i don't think it makes sense installing anyhow extension just because it looks good or with good and attractive features but instead installing and sticking to those which have been proven to be genuine for a long time. As this is a matter of money, at all times, safety should not be taken for granted.
terrific
Hero Member
*****
Offline Offline

Activity: 2170
Merit: 506


#SWGT PRE-SALE IS LIVE


View Profile
May 01, 2020, 06:44:44 PM
 #3

The more cryptocurrencies grows the more scammers and hackers keeps looking for ways to steal from people then proving the fact that, crypto is highly valuable (depends on the crypto though) no matter how most people sees it. However, this is a call for concern (49 browser extensions is too much) that we should be extremely careful of the type of browser extensions we install, i don't think it makes sense installing anyhow extension just because it looks good or with good and attractive features but instead installing and sticking to those which have been proven to be genuine for a long time. As this is a matter of money, at all times, safety should not be taken for granted.
It's because crypto is valuable and these scammers are probably also the ones that do fraud and hacking with the banks.
Wherever the money is, they are there.
And for you people, always secure the extensions that you use on your browsers and as much as possible, minimize the use of it.


.SWG.io.













..Pre-Sale is LIVE at $0.15..







..Buy Now..







``█████████████████▄▄
``````▄▄▄▄▄▄▄▄▄▄▄▄████▄
````````````````````▀██▄
```▀▀▀▀``▀▀▀▀▀▀▀▀▀▀▀▄███
``````▄▄▄▄▄▄▄▄▄▄▄▄``▄███
``▄▄▄▄▄▄▄```▄▄▄▄▄``▄███
``````````````````▄██▀
```````````████████████▄
````````````````````▀▀███
`````````▀▀▀▀▀▀▀▀▀▀▀▀▄████
```▄▄▄``▄▄▄▄▄▄▄▄▄▄`````███
`▄▄▄▄▄▄▄▄▄``▄▄▄▄▄▄`````███
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀████
```````````````````▄▄████
``▀▀▀▀▀``▀▀▀▀▀▀▀▀▀█████
██``███████████████▀▀

FIRST LISTING
..CONFIRMED..






Findingnemo
Hero Member
*****
Offline Offline

Activity: 2366
Merit: 793


Bitcoin = Financial freedom


View Profile
May 01, 2020, 07:02:04 PM
 #4

Most of the extensions are created in the way to steal user data then only they can make money by selling your data so whenever you install an extension in your device make sure it is not just a random one so you can avoid losing important data like private keys.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
View ArchiveReport to moderator
kingzpro
Member
**
Offline Offline

Activity: 756
Merit: 13

DIFX - Digital Finacial Exchange


View Profile
May 01, 2020, 07:09:33 PM
 #5

Yeah i have always felt that these extensions are never safe. These are like giving access to third party software to your browser and your data which is very risky because you never know their intentions and they can use your data to exploit it or simply access your wallet, card or banking details so never install them.

Nadziratel
Sr. Member
****
Offline Offline

Activity: 1568
Merit: 321


★777Coin.com★ Fun BTC Casino!


View Profile
May 01, 2020, 07:54:47 PM
 #6

These Chrome plugins have always seemed reliable to me. For this reason, I do not use any extension other than the one for translation.
I am sure not all of them is malicious but there is no need to take a risk for this extensions.

adzino
Copper Member
Hero Member
*****
Offline Offline

Activity: 2968
Merit: 574


www.Crypto.Games: Multiple coins, multiple games


View Profile
May 01, 2020, 08:05:45 PM
 #7

I am not surprised at all hearing this. Never trusted those wallet browser extensions. They all together sounds really fishy to be honest. Though I am a little bit surprised that it took them time to realize that those extensions were stealing private keys. Aren't all chrome extension like opensource. I mean everyone is able to read the code right unless they obfuscate it.
Anyway, I think at least this news might make people think twice before adding some random extension or software.

█████████████████████████
███████▄▄▀▀███▀▀▄▄███████
████████▄███▄████████
█████▄▄█▀▀███▀▀█▄▄█████
████▀▀██▀██████▀██▀▀████
████▄█████████████▄████
███████▀███████▀███████
████▀█████████████▀████
████▄▄██▄████▄██▄▄████
█████▀▀███▀▄████▀▀█████
████████▀███▀████████
███████▀▀▄▄███▄▄▀▀███████
█████████████████████████
.
 CRYPTOGAMES 
.
 Catch the winning spirit! 
█▄░▀███▌░▄
███▄░▀█░▐██▄
▀▀▀▀▀░░░▀▀▀▀▀
████▌░▐█████▀
████░░█████
███▌░▐███▀
███░░███
██▌░▐█▀
PROGRESSIVE
      JACKPOT      
██░░▄▄
▀▀░░████▄
▄▄▄▄██▀░░▄▄
░░░▀▀█░░▀██▄
███▄░░▀▄░█▀▀
█████░░█░░▄▄█
█████░░██████
█████░░█░░▀▀█
LOW HOUSE
         EDGE         
██▄
███░░░░░░░▄▄
█▀░░░░░░░████
█▄░░░░░░░░█▀
██▄░░░░░░▄█
███▄▄░░▄██▌
██████████
█████████▌
PREMIUM VIP
 MEMBERSHIP 
DICE   ROULETTE   BLACKJACK   KENO   MINESWEEPER   VIDEO POKER   PLINKO   SLOT   LOTTERY
20kevin20
Legendary
*
Offline Offline

Activity: 1134
Merit: 1597


View Profile
May 01, 2020, 08:17:57 PM
 #8

~
These Chrome extensions targeted users of crypto wallets, such as Ledger, Trezor
~
I'm wondering how this works as long as I don't input my seed anywhere? AFAIK Ledger does not communicate private keys in any way, correct? So I believe the only way they could target Ledger devices was to generate automatically fake txs so users could be deceived into their acceptance.. am I missing something?
Ridwan Fauzi
Full Member
***
Offline Offline

Activity: 1330
Merit: 147


View Profile
May 01, 2020, 11:06:35 PM
 #9

I found this article that I think this have a similarities https://www.cybereason.com/blog/eventbot-a-new-mobile-banking-trojan-is-born

Just a warning to not download any platform from unknown source. You have to go to original source first before you download a platform.
pakhitheboss
Hero Member
*****
Offline Offline

Activity: 2156
Merit: 801


Top Crypto Casino


View Profile WWW
May 02, 2020, 12:57:37 AM
 #10

A other negative publicity for cryptocurrency.

It seems nothing can stop scammers to scam cryptocurrency investors. This is a serious issue and there might be many more which google might have not been able to detect.

I generally do not access my Private key using my browser as I do not have a web wallet. I prefer using desktop wallets.

 

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
CASINO
.
SPORTS
.
RACING
EVENT DETAILS
EURO 2024
TravelMug
Hero Member
*****
Offline Offline

Activity: 2674
Merit: 854



View Profile
May 02, 2020, 02:33:56 AM
 #11

A other negative publicity for cryptocurrency.

It seems nothing can stop scammers to scam cryptocurrency investors. This is a serious issue and there might be many more which google might have not been able to detect.

I generally do not access my Private key using my browser as I do not have a web wallet. I prefer using desktop wallets.

 

I wouldn't say that this is negative though, I will have to look at the bright side, at least Google has removed it and that people should be aware on the dangers of getting yourself involved in crypto currency. If you are here just to make money and you think that it is easy, then think again.

There are a lot of scammers and cyber criminals around, you need to educate ourselves here. Scammers will be always here, but if we have enough knowledge to not get caught by their trick, then it's a win-win situation for us.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
asriloni
Legendary
*
Offline Offline

Activity: 3052
Merit: 1024


Leading Crypto Sports Betting & Casino Platform


View Profile
May 02, 2020, 02:41:03 AM
 #12

This is a serious issue and there might be many more which google might have not been able to detect.


 
That's why we must create a report to the app or any extension that looks suspicious. I have already reported some suspicious extensions and it has already removed too.
There was a lot of fake extension that is still available in the various platform.

I just hope people will aware to use the recommended extension too.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Dhoe
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 510



View Profile
May 02, 2020, 03:10:26 AM
 #13

Simple tips that we can do is never install any extension on your computer, if you use one of the wallets above then I think that's enough as a security for your assets without needing to install any extensions again. I am a Trezor user and until now I never installed Extensions on my browser.
verita1
Member
**
Offline Offline

Activity: 1358
Merit: 81


View Profile
May 02, 2020, 04:12:42 AM
 #14

Google must improve its conditions of use and thorough verification of the developments that wish to host its extensions for users. It's amazing how bad actors take advantage of such a valuable resource to commit their scams.
The malicious extensions were discovered by MyCrypto and PhishFort, which were subsequently reported to Google.

https://medium.com/mycrypto/discovering-fake-browser-extensions-that-target-users-of-ledger-trezor-mew-metamask-and-more-e281a2b80ff9

doctor877
Full Member
***
Offline Offline

Activity: 896
Merit: 115



View Profile WWW
May 02, 2020, 07:50:32 AM
 #15

I. Definitely not a fan of browser extension for whatever purpose it might be. These wallets developers and browser developers should find a way to ensure more security for user that love to use them of maybe remove the extension
davinchi
Legendary
*
Offline Offline

Activity: 2100
Merit: 1058


View Profile
May 02, 2020, 08:22:42 AM
 #16

Google is continuously taking action against all types of scam attempts, that is really good. Moreover, browsers are known for highly vulnerable thing for individuals as hackers usually gets access through browsers. So, avoiding installing extensions in browsers would be one of prevention measurement against hackers. Not sure how many people are following such practices.

These days, before installing apps in mobile phones and installing extensions on browsers, we must take time to make user about the publishers and their credibility. All the above, some veteran forum members suggested about having a dedicated desktop/laptop only for accessing crypto wallets. I am not sure how many people here may afford such separate system for crypto wallets, but we must work on that so that we may secure ourselves from all possible hack attempts.
Crypto_lion
Member
**
Offline Offline

Activity: 630
Merit: 11

NEW MEDICINE:Faster, Safer, Smarter


View Profile
May 02, 2020, 10:26:45 AM
 #17

This is why I always go with hardware wallets . You never know which extension or the exe file that you installed is monitoring your clipboard and stealing your keys.

❱_    ClinTex     ▬▬▬▬▬▬▬▬▬     NEW MEDICINE:   Faster,   Safer,   Smarter
   ❪  TELEGRAM  ❫                 ❪  TWITTER  ❫                 ❪  LINKEDIN  ❫   
██████████████████████   J O I N   ██████████████████████
btc_angela
Hero Member
*****
Offline Offline

Activity: 2646
Merit: 549



View Profile
May 02, 2020, 12:01:41 PM
 #18

This is why I always go with hardware wallets . You never know which extension or the exe file that you installed is monitoring your clipboard and stealing your keys.

I think if we are starting in our crypto journey, most of us doesn't prefer hardware wallet. We buy them when we mature and learn securing our coins specially if we're going to be a long term holder and involves a lot of investment. We can used Adblock or Ublock so that we can't get phished by this malicious websites.

Or if you see once, then look at the reviews of the apps, usually you will find at least one who are going to exposed and say that this browser extensions are malicious and not legit. And then report them, it will take only a couple of minutes of our time.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!