Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Malicious Ethereum Wallet on Chrome Exploits Sui Network to Steal Crypto

Malicious Ethereum Wallet on Chrome Exploits Sui Network to Steal Crypto

Fake Ethereum Tool Exploits Microtransactions to Hide Credential Theft

Kelly Cromley by Kelly Cromley
Nov 14, 2025
in Ethereum News, Market News, News
Reading Time: 3 mins read
0
Ethereum

A fraudulent cryptocurrency wallet extension listed on the Chrome Web Store has been found stealing user seed phrases through an unconventional technique that relies on blockchain microtransactions. Despite containing clearly malicious components, the extension has appeared prominently in search results, raising concerns about oversight on major browser marketplaces.

The extension, known as Safery: Ethereum Wallet, promotes itself as a secure platform for managing Ethereum-based assets. According to a recent analysis released by blockchain security firm Socket, the tool is engineered to extract seed phrases from users the moment they attempt to either create a new wallet or import an existing one. The extension, first uploaded in late September 2025, currently ranks as one of the top search results shown to users looking for Ethereum wallet tools, appearing alongside legitimate offerings such as MetaMask, Wombat, and Enkrypt.

Seed Phrases Leaked Through Synthetic Addresses

Socket’s investigation revealed that the extension compromises security at both entry points offered to users. When a new wallet is created, the tool immediately captures the newly generated seed phrase. When an existing wallet is imported, the phrase is taken at the moment the user enters it. What sets this campaign apart is its method of transmitting stolen information.

Instead of relying on conventional command-and-control servers, the attackers have adopted a method that hides data inside small blockchain transactions. The malware encodes BIP-39 seed phrases into fabricated Sui-style blockchain addresses. It then triggers microtransactions of an extremely small SUI amount—roughly one-millionth of a token—from an attacker-controlled wallet to these synthetic addresses. Socket researcher Kirill Boychenko explained that threat actors continuously monitor the Sui blockchain for such tiny transfers. By decoding the recipient address, they can reconstruct the original seed phrase. This approach enables them to gain complete access to the user’s assets and drain the compromised wallet.

🚨 SECURITY ALERT: Malicious Chrome Extension Stealing Crypto Assets

A fake Ethereum wallet extension "Safery: Ethereum Wallet" is exfiltrating seed phrases by encoding them into #Sui transactions—a highly sophisticated attack method.

⚠️ Extension Name: Safery: Ethereum Wallet… pic.twitter.com/FIEkkq2pau

— GoPlus Security 🚦 (@GoPlusSecurity) November 14, 2025


The tactic works regardless of whether the user is creating a new wallet or importing an existing one. In both cases, the seed phrase is funneled directly into the blockchain-based exfiltration system, placing users at immediate risk.

Multiple Warning Signs Ignored by Users

Investigators highlighted several signs that could have alerted users to the extension’s suspicious nature. The tool had no user reviews, contained branding with noticeable grammatical errors, and lacked a dedicated website. Additionally, the developer listed a Gmail address rather than a professional domain, a detail commonly associated with unverified or low-quality extensions.

Independent analysts at Koi Security confirmed Socket’s findings. Their review indicated that the extension actively monitored blockchain activity and converted encoded addresses back into seed phrases. Cybersecurity specialists advised users to install only verified and reputable wallet extensions, warning that all unknown tools should be treated cautiously.

New Attack Method Evades Traditional Detection

Experts noted that this technique poses a challenge for traditional security measures. Boychenko emphasized that the method allows attackers to shift between different blockchains and RPC endpoints effortlessly. Because the technique does not rely on domains, URLs, or consistent extension identifiers, common detection tools are likely to overlook the threat. Security teams have been urged to treat unexpected blockchain RPC calls from web browsers as high-risk indicators.

Specialists recommend that defenders screen browser extensions for signs of malicious activity, including mnemonic encoders, synthetic address generators, and hard-coded seed phrases. They also advise blocking tools that attempt blockchain interactions during wallet creation or import flows.

Users have been encouraged to monitor all wallet activity closely, as even very small, unexpected transactions could signal malicious behavior. As of mid-November 2025, the fake extension remained available for download, with its latest update appearing just one day earlier.

Previous Post

Nigeria Expands Blockchain Capacity Through New Tech Partnership

Next Post

Alibaba Prepares Blockchain Payment Revamp for Global Trade

Related Posts

hash codex

Hashcodex Introduces Multi-Chain Web3 Wallet Solutions

by Kelly Cromley
Mar 16, 2026
0

Hashcodex, a company specializing in Web3 wallet development, has introduced a suite of services designed to help businesses provide digital...

fognet

FOGNET and 21DAO Partner to Expand Web3 DeFi Ecosystem

by Kelly Cromley
Mar 16, 2026
0

FOGNET, a blockchain network specializing in high-speed infrastructure and real estate tokenization, has formed a strategic partnership with 21DAO, a...

TermiX AI

TermiX.AI Partners With GoPlus to Strengthen Web3 AI Security

by Kelly Cromley
Mar 16, 2026
0

TermiX.AI, an artificial intelligence infrastructure platform designed to help enterprises and developers deploy and scale intelligent systems, has announced a...

unibase

Unibase and HyperGPT Partner to Advance AI Agents

by Kelly Cromley
Mar 16, 2026
0

Unibase, a decentralized artificial intelligence memory infrastructure designed to verify and store information for autonomous AI agents, has announced a...

planet hares

Planet Hares Partners With SlideFunBot to Expand Web3 Metaverse

by Kelly Cromley
Mar 16, 2026
0

Planet Hares, a metaverse ecosystem focused on empowering Web3 users and blockchain projects, has announced a strategic collaboration with SlideFunBot,...

TRON

TRON Joins Mastercard Program to Advance Crypto Payments

by Kelly Cromley
Mar 15, 2026
0

The blockchain network TRON has entered into a strategic collaboration with the Mastercard Crypto Partner Program, highlighting the growing alignment...

Next Post
Alibaba Group

Alibaba Prepares Blockchain Payment Revamp for Global Trade

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

hash codex
Market News

Hashcodex Introduces Multi-Chain Web3 Wallet Solutions

by Kelly Cromley
Mar 16, 2026
fognet
Market News

FOGNET and 21DAO Partner to Expand Web3 DeFi Ecosystem

by Kelly Cromley
Mar 16, 2026
TermiX AI
Market News

TermiX.AI Partners With GoPlus to Strengthen Web3 AI Security

by Kelly Cromley
Mar 16, 2026
unibase
Market News

Unibase and HyperGPT Partner to Advance AI Agents

by Kelly Cromley
Mar 16, 2026
planet hares
Market News

Planet Hares Partners With SlideFunBot to Expand Web3 Metaverse

by Kelly Cromley
Mar 16, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.