Briefing

The malicious “Safery → Ethereum Wallet” Chrome extension successfully compromised user-side security through a sophisticated supply chain attack, leading to the complete loss of control over imported and newly created wallets. This threat is critical because the extension covertly exfiltrates the user’s seed phrase by encoding it into synthetic Sui addresses and broadcasting microtransactions, a method that evades standard network traffic monitoring. The fraudulent application achieved a dangerous level of visibility, ranking fourth in Chrome Web Store searches for “Ethereum Wallet” alongside legitimate providers.

The intricate design showcases a futuristic device with a central, translucent blue optical component, surrounded by polished metallic surfaces and subtle dark blue accents. A small orange button is visible, hinting at interactive functionality within its complex architecture

Context

The prevailing risk in the user-facing Web3 ecosystem remains the lack of due diligence against social engineering and the inherent trust placed in application store listings. This attack surface is exacerbated by the ease with which sophisticated malware can mimic legitimate tools and bypass manual review processes, exploiting the user’s reliance on platform-verified applications. The primary defense layer, the browser environment, is consistently targeted as the weakest link in the chain of custody for private keys.

A close-up view reveals a polished, metallic object, possibly a hardware wallet, partially encased within a vibrant blue, translucent framework. The entire structure is visibly covered in a layer of white frost, creating a striking contrast and suggesting extreme cold

Analysis

The exploit’s technical core is its on-chain command-and-control (C2) mechanism, which requires no external HTTP communication, thus avoiding typical network-level detection. When a user creates or imports a wallet, the extension’s malicious code encodes the BIP-39 mnemonic into a series of synthetic Sui-style addresses. A hardcoded attacker-controlled wallet then broadcasts minute 0.000001 SUI transactions to these unique recipient addresses. By monitoring the Sui blockchain, the attacker can precisely decode the recipient address data to reconstruct the victim’s full seed phrase, achieving silent, complete wallet compromise.

A smooth, white sphere is embedded within a dense, spiky field of bright blue crystals and frosted white structures, all set against a backdrop of dark, metallic, circuit-like platforms. This scene visually represents the core of a digital asset or a key data point within a decentralized system, perhaps akin to a seed phrase or a critical smart contract parameter

Parameters

  • Vulnerability Class → Supply Chain Attack via Malicious Browser Extension.
  • Exfiltration MethodSeed Phrase Encoding into Sui Addresses via Microtransactions.
  • Affected Component → User-side Browser Environment and BIP-39 Mnemonic Generation/Import Logic.
  • Market Placement → Ranked 4th in Chrome Web Store search results for “Ethereum Wallet,” lending false legitimacy.

A sophisticated, transparent blue and metallic device features a central white, textured spherical component precisely engaged by a fine transparent tube. Visible through the clear casing are intricate internal mechanisms, highlighting advanced engineering

Outlook

Immediate mitigation requires all users to audit their browser extensions and immediately migrate assets from any wallet created or imported via unverified sources. This incident establishes a new best practice for security auditing → a requirement to scan all client-side code for mnemonic encoders and hidden on-chain exfiltration logic, specifically targeting multi-chain address generation and microtransaction broadcasting. The industry must now address the systemic risk of malicious supply chain attacks via major app stores.

A high-resolution, abstract rendering showcases a central, metallic lens-like mechanism surrounded by swirling, translucent blue liquid and structured conduits. This intricate core is enveloped by a thick, frothy layer of white bubbles, creating a dynamic visual contrast

Verdict

This novel on-chain exfiltration technique represents a critical evolution in wallet-draining malware, confirming that the user’s browser environment is the most vulnerable frontier in digital asset security.

Browser extension, seed phrase theft, mnemonic exfiltration, supply chain attack, social engineering, microtransaction data, on-chain C2, BIP-39 encoding, wallet compromise, digital asset security, Chrome Web Store, fraudulent application, web3 security, user-side vulnerability, Sui network addresses, micro transaction, covert data leak, asset drainage Signal Acquired from → thehackernews.com

Micro Crypto News Feeds