Welcome DT News

  • CONTACT
  • ABOUT US
Deythere
  • Home
  • News
    Vanguard Crypto ETF Breakthrough
    NewsCryptoMarket

    Vanguard Approves Crypto ETF Trading for 50 Million Clients

    This article was first published on Deythere. Vanguard, a traditional conservative investment…

    By
    Jane Omada Apeh
    December 14, 2025
    What Really Happens Inside Liquidity Pools? How They Work and Why They Matter
    NewsCryptoMarket
    How Liquidity Pools Power DeFi: Risks, Rewards, and Real Use Cases
    December 13, 2025
    Gold-Backed Token
    CryptoMarketNews
    Bhutan Unveils Sovereign Gold-Backed Token TER on Solana
    December 12, 2025
    Coinbase Launches Solana On-Chain Trading, Unlocking Instant Access for 100M Users
    NewsCryptoMarket
    Coinbase Launches Solana On-Chain Trading, Unlocking Instant Access for 100M Users
    December 12, 2025
    CFTC Withdraws 2020 Crypto Guidance Exchanges Gain Major New Freedom
    NewsCryptoMarket
    CFTC Withdraws 2020 Crypto Guidance: Exchanges Gain Major New Freedom
    December 12, 2025
  • Cryptocurrency
    Vanguard Crypto ETF Breakthrough
    Vanguard Approves Crypto ETF Trading for 50 Million Clients
    12 Min Read
    What Really Happens Inside Liquidity Pools? How They Work and Why They Matter
    How Liquidity Pools Power DeFi: Risks, Rewards, and Real Use Cases
    20 Min Read
    Gold-Backed Token
    Bhutan Unveils Sovereign Gold-Backed Token TER on Solana
    6 Min Read
    Coinbase Launches Solana On-Chain Trading, Unlocking Instant Access for 100M Users
    Coinbase Launches Solana On-Chain Trading, Unlocking Instant Access for 100M Users
    6 Min Read
    CFTC Withdraws 2020 Crypto Guidance Exchanges Gain Major New Freedom
    CFTC Withdraws 2020 Crypto Guidance: Exchanges Gain Major New Freedom
    6 Min Read
    Hedera Edges Into NATO DIANA's 2026 Cohort: What Neuron Brings to the Battlefield
    Hedera Breaks Into Defense Tech: Neuron Joins NATO’s DIANA Innovation Program
    7 Min Read
    Previous Next
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Reading: Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
Share
Bitcoin Bitcoin (BTC) $89,537.67 ↓ -0.85%
Ethereum Ethereum (ETH) $3,117.19 ↓ -0.15%
Tether USDt Tether USDt (USDT) $1.00 ↓ -0.01%
BNB BNB (BNB) $889.96 ↓ -0.68%
XRP XRP (XRP) $2.00 ↓ -1.14%
USDC USDC (USDC) $1.00 ↑ 0.01%
Solana Solana (SOL) $131.45 ↓ -1.27%
TRON TRON (TRX) $0.28 ↑ 2.69%
Dogecoin Dogecoin (DOGE) $0.14 ↓ -1.45%
Cardano Cardano (ADA) $0.40 ↓ -1.56%
Bitcoin Cash Bitcoin Cash (BCH) $565.35 ↓ -3.30%
Hyperliquid Hyperliquid (HYPE) $29.04 ↓ -1.25%
Chainlink Chainlink (LINK) $13.56 ↓ -1.13%
UNUS SED LEO UNUS SED LEO (LEO) $9.21 ↓ -1.25%
Stellar Stellar (XLM) $0.23 ↓ -2.27%
Monero Monero (XMR) $403.56 ↓ -3.29%
Zcash Zcash (ZEC) $401.95 ↓ -7.70%
Ethena USDe Ethena USDe (USDe) $1.00 ↓ -0.01%
Litecoin Litecoin (LTC) $80.69 ↓ -1.02%
Sui Sui (SUI) $1.57 ↓ -2.18%
Avalanche Avalanche (AVAX) $13.14 ↓ -1.29%
Dai Dai (DAI) $1.00 ↓ -0.01%
Hedera Hedera (HBAR) $0.12 ↓ -3.40%
Shiba Inu Shiba Inu (SHIB) $0.00 ↓ -1.95%
Mantle Mantle (MNT) $1.31 ↓ -0.02%
PayPal USD PayPal USD (PYUSD) $1.00 ↓ 0.00%
Toncoin Toncoin (TON) $1.56 ↓ -3.14%
World Liberty Financial World Liberty Financial (WLFI) $0.14 ↓ -3.20%
Cronos Cronos (CRO) $0.10 ↓ -1.69%
Uniswap Uniswap (UNI) $5.40 ↓ -1.99%
Polkadot Polkadot (DOT) $2.00 ↓ -1.55%
Bittensor Bittensor (TAO) $286.35 ↓ -2.80%
Aave Aave (AAVE) $193.51 ↓ -1.24%
World Liberty Financial USD World Liberty Financial USD (USD1) $1.00 ↓ -0.02%
Canton Canton (CC) $0.07 ↑ 4.88%
Bitget Token Bitget Token (BGB) $3.56 ↓ -1.14%
OKB OKB (OKB) $111.09 ↓ -3.70%
Aster Aster (ASTER) $0.94 ↓ -2.60%
MemeCore MemeCore (M) $1.77 ↓ -2.22%
NEAR Protocol NEAR Protocol (NEAR) $1.63 ↓ -1.24%
Ethereum Classic Ethereum Classic (ETC) $13.08 ↓ -0.76%
Ethena Ethena (ENA) $0.24 ↓ -3.07%
Pepe Pepe (PEPE) $0.00 ↓ -1.40%
Internet Computer Internet Computer (ICP) $3.17 ↓ -2.47%
Pi Pi (PI) $0.21 ↓ -0.98%
Tether Gold Tether Gold (XAUt) $4,330.37 ↑ 0.57%
PAX Gold PAX Gold (PAXG) $4,341.51 ↑ 0.56%
Ondo Ondo (ONDO) $0.45 ↓ -2.80%
Global Dollar Global Dollar (USDG) $1.00 ↓ -0.04%
Worldcoin Worldcoin (WLD) $0.58 ↓ -1.77%
KuCoin Token KuCoin Token (KCS) $10.64 ↓ -0.43%
Sky Sky (SKY) $0.06 ↓ -1.85%
Polygon (prev. MATIC) Polygon (prev. MATIC) (POL) $0.12 ↑ 0.03%
Aptos Aptos (APT) $1.66 ↓ -1.78%
Kaspa Kaspa (KAS) $0.04 ↓ -4.49%
Arbitrum Arbitrum (ARB) $0.21 ↓ -3.50%
OFFICIAL TRUMP OFFICIAL TRUMP (TRUMP) $5.49 ↓ -1.24%
Algorand Algorand (ALGO) $0.12 ↓ -1.60%
Cosmos Cosmos (ATOM) $2.14 ↓ -1.64%
Ripple USD Ripple USD (RLUSD) $1.00 ↓ -0.02%
VeChain VeChain (VET) $0.01 ↓ -3.18%
Flare Flare (FLR) $0.01 ↓ -1.82%
Filecoin Filecoin (FIL) $1.34 ↓ -1.08%
Pump.fun Pump.fun (PUMP) $0.00 ↓ -3.96%
Quant Quant (QNT) $78.08 ↓ -3.06%
XDC Network XDC Network (XDC) $0.05 ↓ -1.56%
GateToken GateToken (GT) $10.48 ↑ 0.40%
Sei Sei (SEI) $0.13 ↓ -3.13%
MYX Finance MYX Finance (MYX) $3.21 ↑ 3.48%
Render Render (RENDER) $1.51 ↓ -2.22%
USDD USDD (USDD) $1.00 ↓ -0.04%
Bonk Bonk (BONK) $0.00 ↓ -0.71%
PancakeSwap PancakeSwap (CAKE) $2.16 ↓ -4.37%
Pudgy Penguins Pudgy Penguins (PENGU) $0.01 ↓ -4.92%
First Digital USD First Digital USD (FDUSD) $1.00 ↑ 0.06%
Story Story (IP) $1.84 ↓ -2.65%
Jupiter Jupiter (JUP) $0.20 ↓ -3.18%
Nexo Nexo (NEXO) $0.96 ↓ -1.80%
Optimism Optimism (OP) $0.31 ↓ -1.13%
Artificial Superintelligence Alliance Artificial Superintelligence Alliance (FET) $0.24 ↓ -2.05%
Curve DAO Token Curve DAO Token (CRV) $0.38 ↓ -3.78%
Immutable Immutable (IMX) $0.27 ↓ -2.19%
Lido DAO Lido DAO (LDO) $0.60 ↑ 0.00%
Injective Injective (INJ) $5.28 ↓ -1.46%
Dash Dash (DASH) $42.14 ↓ -7.06%
Aerodrome Finance Aerodrome Finance (AERO) $0.58 ↓ -6.52%
Tezos Tezos (XTZ) $0.49 ↓ -2.93%
Virtuals Protocol Virtuals Protocol (VIRTUAL) $0.78 ↓ -3.33%
Stacks Stacks (STX) $0.28 ↓ -3.14%
SPX6900 SPX6900 (SPX) $0.55 ↓ -6.98%
Starknet Starknet (STRK) $0.11 ↓ -0.17%
TrueUSD TrueUSD (TUSD) $1.00 ↓ -0.03%
AB AB (AB) $0.01 ↓ -0.24%
ether.fi ether.fi (ETHFI) $0.81 ↓ -1.52%
Merlin Chain Merlin Chain (MERL) $0.46 ↓ -0.25%
Celestia Celestia (TIA) $0.56 ↓ -3.81%
Kaia Kaia (KAIA) $0.07 ↓ -1.56%
FLOKI FLOKI (FLOKI) $0.00 ↓ -0.85%
The Graph The Graph (GRT) $0.04 ↓ -2.16%
Trust Wallet Token Trust Wallet Token (TWT) $0.99 ↑ 1.12%
DeythereDeythere
Font ResizerAa
  • Home
  • Crypto
  • Market
  • News
  • Blockchain
  • Contact
Search
  • Home
  • News
  • Cryptocurrency
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Have an existing account? Sign In
Follow US
© DT News. All Rights Reserved.
Deythere > News > News > Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
NewsCryptoMarket

Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Jane Omada ApehMuhammad Saad
Last updated: November 24, 2025 1:04 pm
By
Jane Omada Apeh
Muhammad Saad
Published November 24, 2025
Published November 24, 2025
Share

This article was first published on Deythere.

Contents
  • Disguised to be a Genuine Wallet But Malicious Inside
  • The Stealth Attack: Sui Encodes The Seed Phrase 
  • Why It Went on So Long: Failures in Chrome Store Vetting
  • How Users Were Warned and What They Can Do
  • A Warning for the Crypto Ecosystem
  • Conclusion
  • Glossary
  • Frequently Asked Questions About Chrome Wallet Scam
    • How did the Safery extension go undetected?
    • Did the extension impersonate a popular wallet?
    • If someone used Safery can they get money back?
    • How do I know if a wallet extension is safe?
    • Will other blockchains be vulnerable to similar attacks?
    • References

A seemingly legitimate Chrome extension dubbed “Safery: Ethereum Wallet” has been caught stealing users’ seed phrases in the background. 

Instead of servers or classic phishing, the extension had stored mnemonic phrases using tiny on-chain transactions on Sui coded in a way that made it feel like everyone had been robbed virtually unnoticed. 

The insidiousness of these smart contracts enabled attackers to piece together the wallet recovery phrases of users and deplete their assets. This Chrome wallet scam exposes a new attack vector that abuses the blockchain itself to enable data exfiltration.

Disguised to be a Genuine Wallet But Malicious Inside

The “Safery: Ethereum Wallet” app resembled the kind of neat, safe and secure wallet users would want to store money in. 

It showed up in the Chrome Web Store as one of the top search results for “Ethereum wallet,” alongside popular browser extensions like MetaMask, Wombat and Enkrypt. 

Its publisher page was minimal, the description focused on security and it claimed to store keys locally giving a perception that users were dealing with something safe. 

The extension even requested to work on all websites, a permission that is common for wallet extensions, so there weren’t obvious alarms going off for typical users.

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui

The Stealth Attack: Sui Encodes The Seed Phrase 

Upon installation, Safery didn’t call the command-and-control server to transfer data. Instead, as Socket’s Threat Research Team discovered, It encoded the seed phrase, the 12- or 24-word recovery phrase used to restore a wallet on its native blockchain in synthetic Sui-style blockchain addresses. 

The extension then sent a very small number of SUI tokens (like 0.000001 SUI) to those manipulated addresses from wallets owned by the attacker. 

By observing these transactions on the Sui blockchain and decoding the recipient addresses, threat actors would be able to determine the user’s full seed phrase.

Socket’s reverse engineering protocol revealed that each word in the seed phrase would be translated to its index in a standard BIP-39 list and then packed into a hex string, padded and interpreted as a fake Sui address. 

This sidestepped classic network calls or suspicious-looking HTTP traffic, as the exfiltration “occurred” on the blockchain.

Why It Went on So Long: Failures in Chrome Store Vetting

Part of how Safery reached so high in the Web Store ranks has to do with how Chrome’s Extension marketplace is set up. 

With the store’s algorithm heaving in favour of install count, review velocity, and average rating rather than deep security vetting. Since Safery generated fake 5-star reviews so quickly, it started to gain traction. 

Its description was polished and its permissions appeared routine, allowing it to slip past Google’s more aggressive security checks.

Even after researchers raised an alarm about the threat, the removal wasn’t immediate. 

According to security teams, the fact that Safery’s activity did not include suspicious on-chain behavior but rather presence on-chain and no peculiar external network-related actions, had made conventional malware detection mechanisms less applicable.

How Users Were Warned and What They Can Do

Socket and several cybersecurity outlets raised red flags as soon as they discovered Safery’s behavior pattern. 

They encourage users to never input their seed phrases into unfamiliar, or unverified extensions. 

Whenever they do install a wallet extension, users should make sure to inspect the publisher’s reputation, see if there is an actual website or GitHub repository and scout reviews for patterns such as common generic praise.

If someone believes there is a chance that they have used Safery or any other similarly malicious extension, experts recommend uninstalling the extension at once, revoking all approvals (ERC-20 or elsewhere), and sweeping funds to a new wallet with a secure model of device. 

These steps will limit damage but any wallet touched by Safery is compromised.

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui

A Warning for the Crypto Ecosystem

This vulnerability that led to this chrome wallet scam runs deeper. Browser wallets themselves are fundamentally unsafe. Although they offer ease of use and access to DApps, they expose large attack surfaces. 

Mixing UI legitimacy with stealthy on-chain exfiltration allowed the Safery extension to evade conventional anti-malware security mechanisms.

Security researchers are demanding fixes. 

Suggestions include automatic flagging of extensions that request seed phrase input, better permissions checks, and for there to be a way of verifying publishers i.e. making sure that a wallet really is from a project whose source has been examined according to standards. 

For users, it’s a hard lesson: not every Chrome wallet is secure, and trust should be earned rather than freely given.

Conclusion

The Safery chrome wallet scam is among the most sophisticated crypto malware. By sneaking seed phrases into tiny-size Sui blockchain transactions, the attackers side-stepped conventional detection and constructed an invisible exfiltration channel. 

The Chrome Store hacker abused the trust in Chrome Store, had elevated itself from fake reviews and even utilized the blockchain itself to spill private data. 

The lesson here for wallet users is obvious: always scrutinize extensions, watch the blockchain traffic and approach seed phrase input with extreme caution.

Glossary

Seed Phrase (Mnemonic): List of 12 or 24 words that can be used as a backup to recover wallet and access funds.

Microtransaction: The smallest of blockchain transactions; in this case, sent to move data elsewhere.

BIP-39: A mnemonic seed phrase standard used by many crypto wallets.

Command-and-Control (C2): A server or infrastructure operated by attackers to which data that has been stolen are transmitted.

RPC (Remote Procedure Call): Protocol by which wallets communicate with blockchain nodes.

Frequently Asked Questions About Chrome Wallet Scam

How did the Safery extension go undetected?

Instead of transmitting data over HTTP, it encoded the secret into seemingly legit Sui blockchain transactions, bypassing common malware detection.

Did the extension impersonate a popular wallet?

No, Safery carved its own path. It wasn’t impersonating MetaMask or an existing brand, which could have made it easier to spot.

If someone used Safery can they get money back?

Recovery is hard if seed phrase were leaked. The best course of action is to transfer their funds to a different wallet with newly generated seed.

How do I know if a wallet extension is safe?

Look for developer reputation, active website or repo, good consistent reviews and whether the extension requests seed phrases in insecure contexts.

Will other blockchains be vulnerable to similar attacks?

Experts caution that this method could be mimicked with other public blockchains, not just Sui.

References

SC Media

The Hacker News

Cointelegraph

Cyberwarzone

Daily CyberSecurity

Malware Analysis

Advertising

For advertising inquiries, please email . [email protected] or Telegram

SEC Chair Atkins Narrows the Field: ‘Very Few Tokens Are Securities’

XRP Coin Re-Listed on This Exchange! What You Need to Know

Canary Capital Files First-Ever U.S. Meme Coin ETF for MOG Coin

Solana Outperforms Ethereum’s Early Years With $2.85B in Annual Revenue

Trump Executive Order Puts Europe on High Alert for Digital Currency

TAGGED:Chrome StoreChrome Store VettingChrome Wallet Scamcrypto wallet hackCrypto Wallet SecuritySafery extensionSafery: Ethereum WalletSeed Phrase hackWallet Hack

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
ByJane Omada Apeh
Follow:
Omada is a dedicated crypto journalist with a passion for making the fast-paced world of digital assets understandable and engaging. With years of experience covering cryptocurrency and blockchain innovation, she offers readers more than just the headlines. She provides context, clarity, and depth. Her work spans everything from market trends and regulatory updates to emerging technologies and real-world use cases that are shaping the future of finance. Omada strives to bridge the gap between complex crypto concepts and everyday readers, ensuring that both seasoned investors and curious newcomers can find value in her insights. Her mission is simply to inform, inspire, and keep her audience one step ahead in the ever-evolving crypto universe.
ByMuhammad Saad
Follow:
Muhammad Saad serves as an editor at Deythere, dedicated to delivering content that is sharp, insightful, and reader-friendly. With extensive experience in digital journalism, Saad focuses on connecting the world of cryptocurrency, blockchain, and finance with everyday audiences. From market insights and breaking stories to analytical features and predictions, he ensures every article is factual, engaging, and easy to grasp.
Previous Article Polygon Partnerships Polygon Partnerships Bring Big Institutions Onboard in November 2025
Next Article image 360 Bitcoin Rebounds Lift Dogecoin and Shiba Inu While Apeing ($APEING) Whitelist Signals Next Top Crypto Presale News
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Bitcoinbitcoin
$89,489.00
24h Volume
$36,344,911,055
Market Cap
$1,785,620,846,403
24h Low/High
$87,892.00 / $90,321.00
24h ▼0.91%
7d ▼2.08%
Subscribe to our newslettern

Get Newest Articles Instantly!

Popular News
AI regulations
AI Regulations Discussed at United Nations Conference
gorilla
Gorilla Sudden Ascent in the Crypto Market
dog runes 1
BNB Bull Run Unpacking the Recent Surge in Market Valuation
bitcoin
Bitcoin Surges Amidst Optimistic Market Conditions
trump coin
Super Trump Coin Soars Analyzing Its Recent Surge in the Crypto Market
mogg coin
Mog Coin Surges Unpacking Its Rise and Future Prospects in Crypto
pendle coin
Pendle Soars Analyzing Its Recent Price Surge and Market Dynamics
stack coin
Stacks (STX) Sees Significant Gains with an 11.77% Surge in the Crypto Market

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Deythere

DT News influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Menu

  • Home
  • News
© DT News. All Rights Reserved.
Banner 1
Banner 2
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

  • English