If you run a crypto wallet as a browser extension, today is the day to open your extension list. In August 2026 the security firm Socket disclosed two separate campaigns in which extensions for Firefox, Chrome and Edge harvested recovery phrases, private keys and login credentials for crypto exchanges. The second of those reports was written up on August 30 and is therefore one day old. What is affected is precisely the place where many investors handle their wallet every day.
Malicious Browser Extensions Steal Crypto Wallets
If you run a crypto wallet as a browser extension, today is the day to open your extension list. In August 2026 the security firm Socket disclosed two separate campaigns in which extensions for Firefox, Chrome and Edge harvested…
CryptoTicker
Publisher
Aug 31, 2026 at 6:20 AM UTC · 13 Min. Lesezeit

A browser extension is a small add-on program that runs inside the browser and holds permission to read and change the content of the pages you visit. That same permission is what makes it useful to wallet providers and valuable to attackers.
Browser Extensions as Wallet Thieves: What Socket Found in August 2026
Socket is a security firm specialising in software supply chains that examines packages and extensions for malicious code. Its researchers published two findings within ten days that show the same pattern and yet do not belong together.
The first report is dated August 20, 2026 and concerns the Firefox marketplace: 77 extension identities are connected according to Socket's analysis, 40 of them confirmed malicious. The second report circulated between August 28 and 30 and concerns Chrome and Edge: 19 extensions, 18 of them for Chrome and one for Edge, carried a wallet drainer. A wallet drainer is malicious code that empties a balance to an outside address in a single operation instead of siphoning off individual amounts.
Article Intelligence
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
