A deceptive Ethereum wallet extension lurking in Google’s Chrome Web Store is secretly siphoning users’ seed phrases, putting millions in crypto assets at risk.

Dubbed “Safery: Ethereum Wallet,” this malicious add-on ranks suspiciously high in search results—snagging the No. 4 spot alongside trusted names like MetaMask—while hiding a crafty backdoor that encodes and broadcasts sensitive data through tiny blockchain transactions.
Blockchain security firm Socket sounded the alarm in a fresh report, urging crypto holders to double-check their tools before it’s too late. In an era of rising digital wallet scams, this incident underscores the perils of convenience over caution in the wild west of Web3.
How the Backdoor Works: A Masterclass in Stealthy Theft
At first glance, Safery promises “reliable and secure” management of Ethereum-based assets, complete with easy setup for new or imported wallets. But beneath the hood, it’s a thief in disguise. When users generate a fresh BIP-39 mnemonic seed phrase or import an existing one, the extension doesn’t just store it locally. Instead, it ingeniously encodes the phrase into a series of fake Sui blockchain addresses—Sui being a high-speed layer-1 network unrelated to Ethereum.
From there, the real trick unfolds: The extension triggers minuscule 0.000001 SUI transactions from a wallet controlled by the hackers, sending these tiny amounts to the encoded addresses. To the untrained eye, these look like innocuous network pings. But for the threat actor, it’s a goldmine—decoding the recipient addresses reconstructs the full seed phrase, granting instant access to victims’ funds. Whether you’re a newbie creating your first wallet or a veteran importing holdings, the compromise happens in seconds, with no flashy alerts to tip you off. Socket’s analysis reveals this as a novel twist on old-school phishing, blending Ethereum’s popularity with Sui’s obscurity for maximum stealth.
Red Flags and the Growing Threat Landscape
Spotting fakes isn’t always easy, but Safery waves several in plain sight. Zero user reviews? Check. Branding riddled with grammatical goofs and no official website? Double check. The developer account ties back to a generic Gmail address, a far cry from the polished profiles of legit players. Yet, its prime positioning in Chrome searches shows how even giants like Google can be gamed by savvy scammers, potentially luring thousands into the trap.
This isn’t an isolated heist—crypto’s booming user base has made browser extensions a hotbed for malware. From clipboard hijackers to fake authenticator apps, bad actors are evolving faster than defenses. Socket’s report, dropped mid-week, highlights how such tools exploit the trust users place in familiar platforms, turning everyday browsing into a high-stakes gamble. As adoption surges, so do the stakes: One leaked seed phrase can wipe out life savings in ETH, NFTs, or DeFi stakes overnight.
Safeguarding Your Stack: Expert Tips to Stay Secure
Don’t panic—yet. Socket and cybersecurity pros emphasize proactive habits over reactive fixes. Start with rigorous vetting: Cross-reference extensions on official sites, scour for community endorsements, and avoid anything with telltale amateur vibes. Treat seed phrases like nuclear codes—never enter them into untrusted interfaces, and use hardware wallets for heavy lifting.
Beyond that, vigilance is key. Regularly audit your transaction history for odd micro-transfers; tools like Etherscan or Sui explorers can flag anomalies early. Enable two-factor authentication everywhere possible, and consider running browser sandboxes or antivirus scans tailored for crypto threats. For Ethereum die-hards, stick to battle-tested options like MetaMask, which boast years of audits and millions of secure users. In the end, the best defense is education: A little due diligence today could save you a fortune tomorrow.