Briefing

The malicious “Safery → Ethereum Wallet” Chrome extension successfully compromised user-side security through a sophisticated supply chain attack, leading to the complete loss of control over imported and newly created wallets. This threat is critical because the extension covertly exfiltrates the user’s seed phrase by encoding it into synthetic Sui addresses and broadcasting microtransactions, a method that evades standard network traffic monitoring. The fraudulent application achieved a dangerous level of visibility, ranking fourth in Chrome Web Store searches for “Ethereum Wallet” alongside legitimate providers.

A close-up reveals a sophisticated, metallic device featuring a translucent blue screen displaying intricate digital patterns and alphanumeric characters. A prominent silver frame with a central button accents the front, suggesting an interactive interface for user input and transaction confirmation

Context

The prevailing risk in the user-facing Web3 ecosystem remains the lack of due diligence against social engineering and the inherent trust placed in application store listings. This attack surface is exacerbated by the ease with which sophisticated malware can mimic legitimate tools and bypass manual review processes, exploiting the user’s reliance on platform-verified applications. The primary defense layer, the browser environment, is consistently targeted as the weakest link in the chain of custody for private keys.

A high-tech, white modular apparatus is depicted in a state of connection, with two primary sections slightly apart, showcasing complex internal mechanisms illuminated by intense blue light. A brilliant, pulsating blue energy stream, representing a secure data channel, actively links the two modules

Analysis

The exploit’s technical core is its on-chain command-and-control (C2) mechanism, which requires no external HTTP communication, thus avoiding typical network-level detection. When a user creates or imports a wallet, the extension’s malicious code encodes the BIP-39 mnemonic into a series of synthetic Sui-style addresses. A hardcoded attacker-controlled wallet then broadcasts minute 0.000001 SUI transactions to these unique recipient addresses. By monitoring the Sui blockchain, the attacker can precisely decode the recipient address data to reconstruct the victim’s full seed phrase, achieving silent, complete wallet compromise.

A close-up view reveals the complex internal workings of a watch, featuring polished metallic gears, springs, and a prominent red-centered balance wheel. Overlapping these traditional horological mechanisms is a striking blue, semi-circular component etched with intricate circuit board patterns

Parameters

  • Vulnerability Class → Supply Chain Attack via Malicious Browser Extension.
  • Exfiltration MethodSeed Phrase Encoding into Sui Addresses via Microtransactions.
  • Affected Component → User-side Browser Environment and BIP-39 Mnemonic Generation/Import Logic.
  • Market Placement → Ranked 4th in Chrome Web Store search results for “Ethereum Wallet,” lending false legitimacy.

A polished metallic square plate, featuring a prominent layered circular component, is securely encased within a translucent, wavy, blue-tinted material. The device's sleek, futuristic design suggests advanced technological integration

Outlook

Immediate mitigation requires all users to audit their browser extensions and immediately migrate assets from any wallet created or imported via unverified sources. This incident establishes a new best practice for security auditing → a requirement to scan all client-side code for mnemonic encoders and hidden on-chain exfiltration logic, specifically targeting multi-chain address generation and microtransaction broadcasting. The industry must now address the systemic risk of malicious supply chain attacks via major app stores.

A luminous blue, fluid-like key with hexagonal patterns is prominently displayed over a complex metallic device. To the right, a blue module with a circular sensor is visible, suggesting advanced security features

Verdict

This novel on-chain exfiltration technique represents a critical evolution in wallet-draining malware, confirming that the user’s browser environment is the most vulnerable frontier in digital asset security.

Browser extension, seed phrase theft, mnemonic exfiltration, supply chain attack, social engineering, microtransaction data, on-chain C2, BIP-39 encoding, wallet compromise, digital asset security, Chrome Web Store, fraudulent application, web3 security, user-side vulnerability, Sui network addresses, micro transaction, covert data leak, asset drainage Signal Acquired from → thehackernews.com

Micro Crypto News Feeds