Welcome DT News

  • CONTACT
  • ABOUT US
Deythere
  • Home
  • News
    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum
    CryptoBitcoinMarketNews

    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum

    Bitcoin price resilience continues to shape market trends, staying strong even as…

    By
    Shravani Dhumal
    March 13, 2026
    TRUMP Memecoin
    CryptoBinanceMarketNews
    TRUMP Memecoin Faces Selling Pressure as $31M in Insider Tokens Hit Binance
    March 13, 2026
    Eightco Funding Hits $125M With ARK and Bitmine Backing as Tom Lee Steps In
    NewsCryptoMarket
    Eightco Raises $125M From ARK Invest, Bitmine and Kraken Parent Payward
    March 13, 2026
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    MarketCryptoNews
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    March 13, 2026
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    CryptoMarketNews
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    March 12, 2026
  • Cryptocurrency
    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum
    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum
    8 Min Read
    TRUMP Memecoin
    TRUMP Memecoin Faces Selling Pressure as $31M in Insider Tokens Hit Binance
    7 Min Read
    Eightco Funding Hits $125M With ARK and Bitmine Backing as Tom Lee Steps In
    Eightco Raises $125M From ARK Invest, Bitmine and Kraken Parent Payward
    8 Min Read
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    9 Min Read
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    9 Min Read
    BONK.fun Hack Exposes Solana Launchpad Security Risks After Domain Takeover
    BONK.fun Hack Exposes Solana Launchpad Security Risks After Domain Takeover
    9 Min Read
    Previous Next
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Reading: Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
Share
Unable to load crypto data. Please refresh the page.

Welcome DT News

  • CONTACT
  • ABOUT US
Deythere
  • Home
  • News
    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum
    CryptoBitcoinMarketNews

    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum

    Bitcoin price resilience continues to shape market trends, staying strong even as…

    By
    Shravani Dhumal
    March 13, 2026
    TRUMP Memecoin
    CryptoBinanceMarketNews
    TRUMP Memecoin Faces Selling Pressure as $31M in Insider Tokens Hit Binance
    March 13, 2026
    Eightco Funding Hits $125M With ARK and Bitmine Backing as Tom Lee Steps In
    NewsCryptoMarket
    Eightco Raises $125M From ARK Invest, Bitmine and Kraken Parent Payward
    March 13, 2026
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    MarketCryptoNews
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    March 13, 2026
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    CryptoMarketNews
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    March 12, 2026
  • Cryptocurrency
    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum
    Bitcoin Price Resilience Grows as Oil Shock Fails to Break BTC Momentum
    8 Min Read
    TRUMP Memecoin
    TRUMP Memecoin Faces Selling Pressure as $31M in Insider Tokens Hit Binance
    7 Min Read
    Eightco Funding Hits $125M With ARK and Bitmine Backing as Tom Lee Steps In
    Eightco Raises $125M From ARK Invest, Bitmine and Kraken Parent Payward
    8 Min Read
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    MiCA Regulation Could Shrink Europe’s Crypto Industry
    9 Min Read
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    BONK.Fun Hack: Conta da equipa invadida para instalar um programa que esvazia carteiras
    9 Min Read
    BONK.fun Hack Exposes Solana Launchpad Security Risks After Domain Takeover
    BONK.fun Hack Exposes Solana Launchpad Security Risks After Domain Takeover
    9 Min Read
    Previous Next
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Reading: Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
Share
Unable to load crypto data. Please refresh the page.
  • Home
  • Crypto
  • Market
  • News
  • Blockchain
  • Contact
Search
  • Home
  • News
  • Cryptocurrency
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Have an existing account? Sign In
Follow US
© DT News. All Rights Reserved.
Deythere > News > News > Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
NewsCryptoMarket

Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Jane Omada ApehMuhammad Saad
Last updated: November 24, 2025 1:04 pm
By
Jane Omada Apeh
Muhammad Saad
Published November 24, 2025
Published November 24, 2025
Share

This article was first published on Deythere.

Contents
  • Disguised to be a Genuine Wallet But Malicious Inside
  • The Stealth Attack: Sui Encodes The Seed Phrase 
  • Why It Went on So Long: Failures in Chrome Store Vetting
  • How Users Were Warned and What They Can Do
  • A Warning for the Crypto Ecosystem
  • Conclusion
  • Glossary
  • Frequently Asked Questions About Chrome Wallet Scam
    • How did the Safery extension go undetected?
    • Did the extension impersonate a popular wallet?
    • If someone used Safery can they get money back?
    • How do I know if a wallet extension is safe?
    • Will other blockchains be vulnerable to similar attacks?
    • References

A seemingly legitimate Chrome extension dubbed “Safery: Ethereum Wallet” has been caught stealing users’ seed phrases in the background. 

Instead of servers or classic phishing, the extension had stored mnemonic phrases using tiny on-chain transactions on Sui coded in a way that made it feel like everyone had been robbed virtually unnoticed. 

The insidiousness of these smart contracts enabled attackers to piece together the wallet recovery phrases of users and deplete their assets. This Chrome wallet scam exposes a new attack vector that abuses the blockchain itself to enable data exfiltration.

Disguised to be a Genuine Wallet But Malicious Inside

The “Safery: Ethereum Wallet” app resembled the kind of neat, safe and secure wallet users would want to store money in. 

It showed up in the Chrome Web Store as one of the top search results for “Ethereum wallet,” alongside popular browser extensions like MetaMask, Wombat and Enkrypt. 

Its publisher page was minimal, the description focused on security and it claimed to store keys locally giving a perception that users were dealing with something safe. 

The extension even requested to work on all websites, a permission that is common for wallet extensions, so there weren’t obvious alarms going off for typical users.

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui

The Stealth Attack: Sui Encodes The Seed Phrase 

Upon installation, Safery didn’t call the command-and-control server to transfer data. Instead, as Socket’s Threat Research Team discovered, It encoded the seed phrase, the 12- or 24-word recovery phrase used to restore a wallet on its native blockchain in synthetic Sui-style blockchain addresses. 

The extension then sent a very small number of SUI tokens (like 0.000001 SUI) to those manipulated addresses from wallets owned by the attacker. 

By observing these transactions on the Sui blockchain and decoding the recipient addresses, threat actors would be able to determine the user’s full seed phrase.

Socket’s reverse engineering protocol revealed that each word in the seed phrase would be translated to its index in a standard BIP-39 list and then packed into a hex string, padded and interpreted as a fake Sui address. 

This sidestepped classic network calls or suspicious-looking HTTP traffic, as the exfiltration “occurred” on the blockchain.

Why It Went on So Long: Failures in Chrome Store Vetting

Part of how Safery reached so high in the Web Store ranks has to do with how Chrome’s Extension marketplace is set up. 

With the store’s algorithm heaving in favour of install count, review velocity, and average rating rather than deep security vetting. Since Safery generated fake 5-star reviews so quickly, it started to gain traction. 

Its description was polished and its permissions appeared routine, allowing it to slip past Google’s more aggressive security checks.

Even after researchers raised an alarm about the threat, the removal wasn’t immediate. 

According to security teams, the fact that Safery’s activity did not include suspicious on-chain behavior but rather presence on-chain and no peculiar external network-related actions, had made conventional malware detection mechanisms less applicable.

How Users Were Warned and What They Can Do

Socket and several cybersecurity outlets raised red flags as soon as they discovered Safery’s behavior pattern. 

They encourage users to never input their seed phrases into unfamiliar, or unverified extensions. 

Whenever they do install a wallet extension, users should make sure to inspect the publisher’s reputation, see if there is an actual website or GitHub repository and scout reviews for patterns such as common generic praise.

If someone believes there is a chance that they have used Safery or any other similarly malicious extension, experts recommend uninstalling the extension at once, revoking all approvals (ERC-20 or elsewhere), and sweeping funds to a new wallet with a secure model of device. 

These steps will limit damage but any wallet touched by Safery is compromised.

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui

A Warning for the Crypto Ecosystem

This vulnerability that led to this chrome wallet scam runs deeper. Browser wallets themselves are fundamentally unsafe. Although they offer ease of use and access to DApps, they expose large attack surfaces. 

Mixing UI legitimacy with stealthy on-chain exfiltration allowed the Safery extension to evade conventional anti-malware security mechanisms.

Security researchers are demanding fixes. 

Suggestions include automatic flagging of extensions that request seed phrase input, better permissions checks, and for there to be a way of verifying publishers i.e. making sure that a wallet really is from a project whose source has been examined according to standards. 

For users, it’s a hard lesson: not every Chrome wallet is secure, and trust should be earned rather than freely given.

Conclusion

The Safery chrome wallet scam is among the most sophisticated crypto malware. By sneaking seed phrases into tiny-size Sui blockchain transactions, the attackers side-stepped conventional detection and constructed an invisible exfiltration channel. 

The Chrome Store hacker abused the trust in Chrome Store, had elevated itself from fake reviews and even utilized the blockchain itself to spill private data. 

The lesson here for wallet users is obvious: always scrutinize extensions, watch the blockchain traffic and approach seed phrase input with extreme caution.

Glossary

Seed Phrase (Mnemonic): List of 12 or 24 words that can be used as a backup to recover wallet and access funds.

Microtransaction: The smallest of blockchain transactions; in this case, sent to move data elsewhere.

BIP-39: A mnemonic seed phrase standard used by many crypto wallets.

Command-and-Control (C2): A server or infrastructure operated by attackers to which data that has been stolen are transmitted.

RPC (Remote Procedure Call): Protocol by which wallets communicate with blockchain nodes.

Frequently Asked Questions About Chrome Wallet Scam

How did the Safery extension go undetected?

Instead of transmitting data over HTTP, it encoded the secret into seemingly legit Sui blockchain transactions, bypassing common malware detection.

Did the extension impersonate a popular wallet?

No, Safery carved its own path. It wasn’t impersonating MetaMask or an existing brand, which could have made it easier to spot.

If someone used Safery can they get money back?

Recovery is hard if seed phrase were leaked. The best course of action is to transfer their funds to a different wallet with newly generated seed.

How do I know if a wallet extension is safe?

Look for developer reputation, active website or repo, good consistent reviews and whether the extension requests seed phrases in insecure contexts.

Will other blockchains be vulnerable to similar attacks?

Experts caution that this method could be mimicked with other public blockchains, not just Sui.

References

SC Media

The Hacker News

Cointelegraph

Cyberwarzone

Daily CyberSecurity

Malware Analysis

Advertising

For advertising inquiries, please email . [email protected] or Telegram

Will Binance and Franklin Templeton Partnership Make 2025 the Year of Tokenized Assets?

U.S. Debt Nears $40 Trillion: What It Means for Bitcoin and Market Liquidity

Don’t Miss 2026’s Next 100x Meme Coin: APEMARS Presale in Spotlight as Official Trump Slides 18% and Greenland Shark Tanks 67%

LTC and TON Once Ran the Play, But Now APEMARS – The Next 100X Crypto Presale Opens the Next Entry to 15,055% ROI

Cardano Foundation Outlines Strategy to Bridge Blockchain and Real-World Utility

TAGGED:Chrome StoreChrome Store VettingChrome Wallet Scamcrypto wallet hackCrypto Wallet SecuritySafery extensionSafery: Ethereum WalletSeed Phrase hackWallet Hack

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
ByJane Omada Apeh
Follow:
Omada is a dedicated crypto journalist with a passion for making the fast-paced world of digital assets understandable and engaging. With years of experience covering cryptocurrency and blockchain innovation, she offers readers more than just the headlines. She provides context, clarity, and depth. Her work spans everything from market trends and regulatory updates to emerging technologies and real-world use cases that are shaping the future of finance. Omada strives to bridge the gap between complex crypto concepts and everyday readers, ensuring that both seasoned investors and curious newcomers can find value in her insights. Her mission is simply to inform, inspire, and keep her audience one step ahead in the ever-evolving crypto universe.
ByMuhammad Saad
Follow:
Muhammad Saad serves as an editor at Deythere, dedicated to delivering content that is sharp, insightful, and reader-friendly. With extensive experience in digital journalism, Saad focuses on connecting the world of cryptocurrency, blockchain, and finance with everyday audiences. From market insights and breaking stories to analytical features and predictions, he ensures every article is factual, engaging, and easy to grasp.
Previous Article Polygon Partnerships Polygon Partnerships Bring Big Institutions Onboard in November 2025
Next Article image 360 Bitcoin Rebounds Lift Dogecoin and Shiba Inu While Apeing ($APEING) Whitelist Signals Next Top Crypto Presale News
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Unable to load data. Please try again later.
Subscribe to our newslettern

Get Newest Articles Instantly!

Popular News
image 909
Game Beta Live, Burns Ahead: Troller Cat Leads the Best Cryptos For Beginners Right Now as Doginme and Andy Move Quietly
image 7
Buy Before 9.97% Price Jump: Troller Cat’s 399% Path Leads Best Crypto to Explode in 2025 as Cat in a Dog’s World Slips and Dogs Jumps
image 31
Pudgy Penguins Price Prediction: ATH in Sight, But Troller Cat Targets $150K Bags First
image 51
Neiro Price Prediction: Neiro Slides 11.8% This Week as Troller Cat Presale Pounces at $0.0001169
image 63
You Blinked on Pepe? Might Wanna Watch the Shadows—Another Meme Beast Is Waking Up
Image fx 53
Coinbase Makes Headlines with Triple Listing Surprise
image 382
312% Room to Run: Troller Cat’s Listing Target Puts It in Top Meme Coins to Invest in This Week as Pepe Falls, Bonk Climbs
image 386
Pudgy Penguins Could Rally 687%, Yet Troller Cat’s Stage 17 ROI Beats the Charts

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Deythere

DT News influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Menu

  • Home
  • News
© DT News. All Rights Reserved.
Banner 1
Banner 2
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

  • English