THREAT INTELLIGENCE REPORT

Browser Extension
Cryptocurrency Wallet
Attack Vectors

Comprehensive analysis of emerging threats targeting cryptocurrency wallet browser extensions: exploitation techniques, known campaigns, and indicators of compromise.

ACTIVE THREAT :: $1.3B stolen in 2023
RECORDED ATTACKS
0
ACTIVE CAMPAIGNS
0
COMPROMISED WALLETS
0
▶ CLICK TO REPLAY
SEED PHRASE
DETECTED
TRANSMITTING TO REMOTE SERVER
0x4f2a…c91b → 185.220.101.47
● SECURE
CRITICAL
DOM Injection via Content Script
Extension injects malicious DOM overlays that intercept seed phrase entry and exfiltrate via encrypted WebSocket to C2 infrastructure.
CVE-2023-44487EXPLOITED IN WILD
CRITICAL
Storage API Seed Harvesting
Abuses chrome.storage.local to read plaintext seed phrases stored by legitimate wallet extensions without triggering permission prompts.
LAZARUS-202312 WALLETS AFFECTED
HIGH
Clipboard Address Hijacking
Background service worker monitors clipboard for cryptocurrency address patterns and replaces with attacker-controlled addresses silently.
WIDESPREAD142 VARIANTS
HIGH
Fake Update Injection
Extension spoofs legitimate wallet update UI, capturing private keys during simulated "migration" flow before user realizes the deception.
PHISHING VECTOR$4.2M LOST
MEDIUM
RPC Endpoint Manipulation
Extension silently modifies wallet RPC endpoints to route transactions through attacker nodes enabling frontrunning and value extraction.
MEV ATTACKON-CHAIN DETECTABLE
MEDIUM
Permission Escalation Chain
Benign extension requests minimal permissions, then uses cross-extension messaging to escalate and gain wallet API access post-installation.
SUPPLY CHAIN3 KNOWN CHAINS
cryptothreat-monitor — live
MALICIOUS DOMAINS
DOMmetamask-update-2024.io
DOMtrustwallet-secure.net
PHISHphantom-wallet-app.com
C2185.220.101.47:8443
C245.153.160.140:443
EXTENSION IDs
nkbihfbeogaeaoehlefnkodbefgpgknn
ejbalbakoplchlghecdalmeeeajnimhm
fhbohimaelbohpjbbldcngcnapndodjp
bfnaelmomeimhlpmgjnjophhpkkoljpa
aeachknmefphepccionboohckonoeemg
BEHAVIORAL SIGNATURES
APIchrome.storage read on vault paths
NETEncrypted WebSocket to non-CDN IP
DOMInput field overlay injection
APIClipboard read without user gesture
NETBeaconing interval 30–120s