Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
cryptocurrency-platform-riskcredential-stealer-activityextension-plugin-hijackdata-exfiltration-method

Malicious Safery Chrome Extension Steals Ethereum Wallet Seed Phrases via Sui Blockchain

Updated 3mo agoFirst seen Nov 13, 20254 sources

A malicious Chrome extension named Safery: Ethereum Wallet was discovered on the Chrome Web Store, masquerading as a legitimate Ethereum wallet while secretly exfiltrating users' seed phrases. The extension encodes the BIP-39 mnemonic seed phrases into synthetic Sui blockchain addresses and sends microtransactions (0.000001 SUI) from a hardcoded attacker-controlled wallet, embedding the sensitive information within normal-looking blockchain transactions. This method allows the threat actor to later decode the recipient addresses and reconstruct the original seed phrase, enabling them to drain victims' cryptocurrency assets without relying on a traditional command-and-control server.

Security researchers from both Socket and Koi Security analyzed the extension, confirming its backdoor functionality and detailing its technical behavior, including the use of a hardcoded Base64 wallet seed and global exposure of sensitive wallet functions in the browser. The extension remained available for download at the time of reporting, and a takedown request was submitted to Google. Users are advised to avoid untrusted wallet extensions and defenders are recommended to scan for mnemonic encoders, synthetic address generators, and suspicious on-chain writing behaviors in browser add-ons to mitigate similar threats.

Share:
Malicious Safery Chrome Extension Steals Ethereum Wallet Seed Phrases via Sui Blockchain
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 12, 20258mo ago

Socket reports the malicious extension and requests Google takedown

Socket's Threat Research Team publicly disclosed the malicious extension, stating it was still live on the Chrome Web Store at the time of reporting. Socket said it submitted a takedown request to Google and asked for the publisher account to be suspended.

Safery uses Sui microtransactions to exfiltrate seed phrases

Researchers found the extension encoded victims' mnemonic seed phrases into one or two synthetic Sui-style addresses and sent 0.000001 SUI microtransactions from an attacker-controlled wallet. This allowed seed theft through on-chain activity instead of traditional HTTP exfiltration or centralized command-and-control infrastructure.

Nov 12, 20242y ago

Malicious 'Safery: Ethereum Wallet' extension is published to Chrome Web Store

A Chrome extension named 'Safery: Ethereum Wallet' was published on the Chrome Web Store while masquerading as a secure Ethereum wallet. It was designed to steal users' BIP-39 seed phrases despite presenting normal wallet features such as wallet import, balance viewing, and ETH transfers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Organizations
5 linked
GoogleSocketPhantom TechnologiesEnkrypt AIMetamask
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.