Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (2,264)
  • Analysis (2,418)
  • Bitcoin (3,018)
  • Blockchain (1,852)
  • DeFi (2,200)
  • Ethereum (2,148)
  • Event (78)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,247)
  • Press Releases (10)
  • Reddit (1,682)
  • Regulation (2,106)
  • Security (2,901)
  • Thought Leadership (3)
  • Videos (43)
Hand picked
  • Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
  • [AMA] Welcome to Hegecoin’s third time back at r/cc!
  • VanEck’s Solana ETF Set to Launch Following SEC 8-A Filing – Details
  • MoonPay Launches New Enterprise Stablecoin Platform Worldwide
  • Here’s what happened on the first day
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Blockchain»Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Blockchain

Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain

November 14, 2025No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


November 13, 2025Delighted LakshmananBrowser Security/Threat Intelligence

Cybersecurity researchers have discovered a malicious Chrome extension that poses as a legitimate Ethereum wallet but hosts functionality to exfiltrate users’ seed phrases.

The name of the extension is “Safery: Ethereum Wallet,” with the threat actor describing it as a “secure wallet for managing Ethereum cryptocurrency with flexible settings.” It was uploaded to the Chrome Web Store on September 29, 2025 and updated on November 12. It is still available for download at the time of writing.

“Marketed as a simple and secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them in Sui addresses and broadcasting microtransactions from a Sui wallet controlled by a threat actor,” said Kirill Boychenko, security researcher at Socket.

DFIR Retention Services

Specifically, the malware in the browser add-on is designed to steal wallet mnemonic phrases by encoding them as fake Sui wallet addresses, and then using microtransactions to send 0.000001 SUI to those wallets from a hard-coded wallet controlled by a threat actor.

The malware’s end goal is to smuggle the seed phrase into normal-looking blockchain transactions without needing to set up a command and control (C2) server to receive the information. Once the transactions are completed, the malicious actor can decode the recipient addresses to reconstruct the original seed phrase and ultimately drain the assets.

“This extension steals wallet seed phrases by encoding them as fake Sui addresses and sending them microtransactions from an attacker-controlled wallet, allowing the attacker to monitor the blockchain, decode the addresses into seed phrases, and drain victims’ funds,” Koi Security notes in an analysis.

To counter the risk posed by the threat, users are advised to stick to reliable wallet extensions. It is recommended that defenders scan extensions for mnemonic encoders, synthetic address generators, and hardcoded seed phrases, as well as block those that write to the chain when importing or creating a wallet.

“This technique allows threat actors to change RPC strings and endpoints with little effort, so detections that rely on specific domains, URLs or extension IDs will not do so,” Boychenko said. “Treat unexpected blockchain RPC calls from the browser as a high signal, especially when the product claims to be a unique chain.”



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article[AMA] Welcome to Hegecoin’s third time back at r/cc!

Related Posts

Blockchain

Why former Sotheby’s chief executive Tad Smith is optimistic about blockchain art – The Art Newspaper

November 14, 2025
Blockchain

Google’s ‘crazy tool’ could make blockchain obsolete – Experts suggest ‘wild’ and ‘exciting’ times ahead in ‘high risk, high reward’ effort

November 14, 2025
Blockchain

Citi: bringing blockchain to the Treasury of tomorrow

November 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Global Experts Unite at PQBD 2025 to Shape the Quantum-Safe Blockchain Era

November 13, 2025

Phuket, Thailand – November 19, 2025 — Abelian is proud to present Post-Quantum Blockchain Day…

Event

Cyprus Fintech Summit 2025: The Mediterranean’s Power Summit for Fintech Leaders

November 5, 2025

The Cyprus Fintech Summit 2025 marks a defining moment in the region’s financial technology landscape. What began…

1 2 3 … 61 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

MoonPay Launches New Enterprise Stablecoin Platform Worldwide

November 14, 2025

DCR Price Tests $55 as 60% Staking Tightens Supply – What’s Next

November 14, 2025

Crypto Treasuries Turn Defensive as Solana Upexi Buyback Adds to Growing DAT Trend

November 14, 2025
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2025 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 96,073.74
ethereum
Ethereum (ETH) $ 3,138.74
tether
Tether (USDT) $ 0.999788
xrp
XRP (XRP) $ 2.27
bnb
BNB (BNB) $ 907.87
solana
Wrapped SOL (SOL) $ 140.48
usd-coin
USDC (USDC) $ 1.00
tron
TRON (TRX) $ 0.292609
staked-ether
Lido Staked Ether (STETH) $ 3,137.68
dogecoin
Dogecoin (DOGE) $ 0.161445