Warning to users of browser extensions from the Chrome Web Store: An Ethereum wallet can steal your security keys without you even noticing.
An Ethereum wallet to avoid on the Chrome Web Store
The analytics site Socket reported the news this week. It highlighted a browser extension that appears secure at first glance: Safery. It is an Ethereum wallet that describes itself as “a reliable and secure browser extension” for managing assets on the Ethereum blockchain.
Released a year ago, this extension contains a backdoor that captures users’ recovery phrases:
[Safery] contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a Sui wallet controlled by a malicious actor.
At the time of writing, Safery is still ranked 4th when searching for “Ethereum wallet” on the Chrome Web Store:

The malicious Safery wallet—avoid it on the Chrome Web Store
A seemingly standard wallet
This extension is dangerous because it appears to do exactly what it’s supposed to do. According to Socket’s report, Safery does indeed allow users to create accounts, import addresses, view recent activity, and send ETH. Users may therefore use it without realizing the danger.
According to the analysis, this scam method is effective and inexpensive for attackers to implement, so we should expect it to be reused:
This technique allows attackers to switch blockchains and RPC endpoints with very little effort, which allows them to evade detection mechanisms based on specific domains, URLs, or extension identifiers.
Browser extensions should generally be treated with caution, and this is especially true when entrusting them with your funds. When in doubt, we recommend using a reputable extension and treating any security claims with skepticism.
This is also a good opportunity to remind readers that keeping cryptocurrencies in a “hot” wallet can be dangerous. It is advisable to use a cold wallet to store the majority of your assets, transferring only what you need.