Welcome DT News

  • CONTACT
  • ABOUT US
Deythere
  • Home
  • News
    Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
    NewsCryptoMarket

    Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel

    This article was first published on Deythere. A seemingly legitimate Chrome extension…

    By
    Jane Omada Apeh
    Muhammad Saad
    November 24, 2025
    Polygon Partnerships
    CryptoMarketNews
    Polygon Partnerships Bring Big Institutions Onboard in November 2025
    November 24, 2025
    institutional RWA tokenization
    MarketCryptoNews
    Why Banks Are Piling Into the $19 Trillion Tokenization Boom
    November 24, 2025
    Ethena And Nunchi Launch nHYPE To Unlock Hyperliquid’s HIP-3 Bond Liquidi
    CryptoBlockchainMarketNews
    Ethena And Nunchi Launch nHYPE To Unlock Hyperliquid’s HIP-3 Bond Liquidity
    November 24, 2025
    Bitcoin ETF Capitulation: $40B Volume Spikes as Institutions Exit
    NewsBitcoinCryptoMarket
    Are Bitcoin ETFs Breaking? $40B Volume Spike and IBIT Outflows Hint at Capitulation
    November 24, 2025
  • Cryptocurrency
    Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
    Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
    8 Min Read
    Polygon Partnerships
    Polygon Partnerships Bring Big Institutions Onboard in November 2025
    5 Min Read
    institutional RWA tokenization
    Why Banks Are Piling Into the $19 Trillion Tokenization Boom
    11 Min Read
    Ethena And Nunchi Launch nHYPE To Unlock Hyperliquid’s HIP-3 Bond Liquidi
    Ethena And Nunchi Launch nHYPE To Unlock Hyperliquid’s HIP-3 Bond Liquidity
    8 Min Read
    Bitcoin ETF Capitulation: $40B Volume Spikes as Institutions Exit
    Are Bitcoin ETFs Breaking? $40B Volume Spike and IBIT Outflows Hint at Capitulation
    9 Min Read
    Why Kohaku is Central to Ethereum Privacy Shift in 2025
    What is Kohaku and Why is it Central to Ethereum Privacy Shift in 2025?
    16 Min Read
    Previous Next
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Reading: Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
Share
Bitcoin Bitcoin (BTC) $93,592.85 ↑ 0.70%
Ethereum Ethereum (ETH) $3,145.17 ↑ 2.67%
Tether USDt Tether USDt (USDT) $1.00 ↑ 0.02%
XRP XRP (XRP) $2.22 ↑ 2.83%
BNB BNB (BNB) $935.24 ↑ 2.64%
Solana Solana (SOL) $140.60 ↑ 6.09%
USDC USDC (USDC) $1.00 ↓ -0.01%
TRON TRON (TRX) $0.29 ↓ -0.42%
Dogecoin Dogecoin (DOGE) $0.16 ↑ 2.95%
Cardano Cardano (ADA) $0.48 ↑ 1.37%
Hyperliquid Hyperliquid (HYPE) $38.71 ↑ 2.49%
Bitcoin Cash Bitcoin Cash (BCH) $520.79 ↑ 2.51%
Zcash Zcash (ZEC) $622.65 ↓ -8.60%
Chainlink Chainlink (LINK) $13.86 ↑ 3.12%
UNUS SED LEO UNUS SED LEO (LEO) $9.42 ↑ 2.88%
Stellar Stellar (XLM) $0.26 ↑ 3.08%
Ethena USDe Ethena USDe (USDe) $1.00 ↓ -0.01%
Monero Monero (XMR) $408.93 ↓ -0.34%
Litecoin Litecoin (LTC) $96.26 ↑ 2.68%
Hedera Hedera (HBAR) $0.15 ↑ 2.02%
Avalanche Avalanche (AVAX) $14.74 ↓ -0.35%
Sui Sui (SUI) $1.68 ↑ 2.42%
Dai Dai (DAI) $1.00 ↑ 0.02%
Shiba Inu Shiba Inu (SHIB) $0.00 ↑ 1.55%
Uniswap Uniswap (UNI) $7.69 ↑ 4.17%
Polkadot Polkadot (DOT) $2.78 ↑ 2.04%
Toncoin Toncoin (TON) $1.81 ↑ 3.42%
Cronos Cronos (CRO) $0.11 ↑ 2.48%
Canton Canton (CC) $0.11 ↑ 3.45%
Mantle Mantle (MNT) $1.11 ↓ -2.03%
World Liberty Financial World Liberty Financial (WLFI) $0.14 ↑ 7.77%
PayPal USD PayPal USD (PYUSD) $1.00 ↑ 0.01%
Bittensor Bittensor (TAO) $332.41 ↑ 4.70%
Aster Aster (ASTER) $1.36 ↑ 10.60%
NEAR Protocol NEAR Protocol (NEAR) $2.32 ↑ 3.12%
Internet Computer Internet Computer (ICP) $5.18 ↓ -1.09%
World Liberty Financial USD World Liberty Financial USD (USD1) $1.00 ↓ -0.01%
Aave Aave (AAVE) $177.39 ↑ 3.91%
Bitget Token Bitget Token (BGB) $3.69 ↓ -2.40%
OKB OKB (OKB) $113.40 ↑ 1.07%
Ethereum Classic Ethereum Classic (ETC) $14.73 ↑ 1.38%
MemeCore MemeCore (M) $2.10 ↓ -2.07%
Aptos Aptos (APT) $2.93 ↑ 4.04%
Pepe Pepe (PEPE) $0.00 ↑ 2.42%
Ethena Ethena (ENA) $0.28 ↑ 5.86%
Pi Pi (PI) $0.23 ↑ 1.71%
Ondo Ondo (ONDO) $0.55 ↑ 1.80%
Worldcoin Worldcoin (WLD) $0.69 ↑ 4.01%
Polygon (prev. MATIC) Polygon (prev. MATIC) (POL) $0.15 ↑ 3.97%
KuCoin Token KuCoin Token (KCS) $12.21 ↑ 1.41%
Tether Gold Tether Gold (XAUt) $4,051.05 ↓ -0.05%
Filecoin Filecoin (FIL) $2.00 ↓ -3.50%
OFFICIAL TRUMP OFFICIAL TRUMP (TRUMP) $7.07 ↑ 0.47%
Algorand Algorand (ALGO) $0.16 ↑ 1.99%
PAX Gold PAX Gold (PAXG) $4,060.95 ↑ 0.03%
Cosmos Cosmos (ATOM) $2.77 ↓ -0.83%
Arbitrum Arbitrum (ARB) $0.24 ↑ 3.27%
VeChain VeChain (VET) $0.02 ↑ 2.03%
Kaspa Kaspa (KAS) $0.04 ↑ 4.43%
Sky Sky (SKY) $0.05 ↑ 3.43%
Global Dollar Global Dollar (USDG) $1.00 ↑ 0.01%
Pump.fun Pump.fun (PUMP) $0.00 ↑ 6.70%
Flare Flare (FLR) $0.01 ↑ 1.40%
Render Render (RENDER) $2.06 ↑ 4.62%
Ripple USD Ripple USD (RLUSD) $1.00 ↑ 0.05%
Dash Dash (DASH) $77.77 ↓ -4.69%
Sei Sei (SEI) $0.15 ↑ 0.31%
First Digital USD First Digital USD (FDUSD) $1.00 ↑ 0.06%
Quant Quant (QNT) $79.52 ↓ -2.14%
Story Story (IP) $2.83 ↑ 0.51%
Starknet Starknet (STRK) $0.20 ↓ -4.24%
XDC Network XDC Network (XDC) $0.05 ↓ -0.72%
Jupiter Jupiter (JUP) $0.27 ↑ 2.38%
GateToken GateToken (GT) $10.87 ↑ 0.28%
Bonk Bonk (BONK) $0.00 ↑ 3.47%
PancakeSwap PancakeSwap (CAKE) $2.41 ↑ 3.30%
Pudgy Penguins Pudgy Penguins (PENGU) $0.01 ↑ 2.61%
Immutable Immutable (IMX) $0.38 ↑ 3.42%
Artificial Superintelligence Alliance Artificial Superintelligence Alliance (FET) $0.32 ↑ 16.52%
Aerodrome Finance Aerodrome Finance (AERO) $0.83 ↑ 7.19%
Virtuals Protocol Virtuals Protocol (VIRTUAL) $1.12 ↑ 3.47%
Optimism Optimism (OP) $0.38 ↑ 3.41%
AB AB (AB) $0.01 ↑ 18.65%
Celestia Celestia (TIA) $0.82 ↑ 0.92%
Morpho Morpho (MORPHO) $1.89 ↑ 4.08%
Injective Injective (INJ) $6.67 ↑ 2.87%
Lido DAO Lido DAO (LDO) $0.74 ↑ 3.70%
Stacks Stacks (STX) $0.35 ↑ 2.58%
Curve DAO Token Curve DAO Token (CRV) $0.45 ↑ 7.30%
Nexo Nexo (NEXO) $0.97 ↓ -0.49%
The Graph The Graph (GRT) $0.06 ↑ 3.00%
Telcoin Telcoin (TEL) $0.01 ↑ 7.33%
MYX Finance MYX Finance (MYX) $2.67 ↑ 6.62%
Tezos Tezos (XTZ) $0.55 ↑ 2.18%
Decred Decred (DCR) $33.19 ↑ 2.17%
ether.fi ether.fi (ETHFI) $0.91 ↑ 5.57%
IOTA IOTA (IOTA) $0.13 ↑ 3.54%
Kaia Kaia (KAIA) $0.09 ↓ -0.64%
FLOKI FLOKI (FLOKI) $0.00 ↑ 3.49%
Pyth Network Pyth Network (PYTH) $0.09 ↑ 3.01%
DeythereDeythere
Font ResizerAa
  • Home
  • Crypto
  • Market
  • News
  • Blockchain
  • Contact
Search
  • Home
  • News
  • Cryptocurrency
  • Pages
    • Contact Us
    • Customize Interests
    • My Bookmarks
Have an existing account? Sign In
Follow US
© DT News. All Rights Reserved.
Deythere > News > News > Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel
NewsCryptoMarket

Why Browser Wallets Are at Risk: Safery Extension Uses Sui as a Secret Data Tunnel

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Jane Omada ApehMuhammad Saad
Last updated: November 24, 2025 1:04 pm
By
Jane Omada Apeh
Muhammad Saad
Published November 24, 2025
Published November 24, 2025
Share

This article was first published on Deythere.

Contents
  • Disguised to be a Genuine Wallet But Malicious Inside
  • The Stealth Attack: Sui Encodes The Seed Phrase 
  • Why It Went on So Long: Failures in Chrome Store Vetting
  • How Users Were Warned and What They Can Do
  • A Warning for the Crypto Ecosystem
  • Conclusion
  • Glossary
  • Frequently Asked Questions About Chrome Wallet Scam
    • How did the Safery extension go undetected?
    • Did the extension impersonate a popular wallet?
    • If someone used Safery can they get money back?
    • How do I know if a wallet extension is safe?
    • Will other blockchains be vulnerable to similar attacks?
    • References

A seemingly legitimate Chrome extension dubbed “Safery: Ethereum Wallet” has been caught stealing users’ seed phrases in the background. 

Instead of servers or classic phishing, the extension had stored mnemonic phrases using tiny on-chain transactions on Sui coded in a way that made it feel like everyone had been robbed virtually unnoticed. 

The insidiousness of these smart contracts enabled attackers to piece together the wallet recovery phrases of users and deplete their assets. This Chrome wallet scam exposes a new attack vector that abuses the blockchain itself to enable data exfiltration.

Disguised to be a Genuine Wallet But Malicious Inside

The “Safery: Ethereum Wallet” app resembled the kind of neat, safe and secure wallet users would want to store money in. 

It showed up in the Chrome Web Store as one of the top search results for “Ethereum wallet,” alongside popular browser extensions like MetaMask, Wombat and Enkrypt. 

Its publisher page was minimal, the description focused on security and it claimed to store keys locally giving a perception that users were dealing with something safe. 

The extension even requested to work on all websites, a permission that is common for wallet extensions, so there weren’t obvious alarms going off for typical users.

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui

The Stealth Attack: Sui Encodes The Seed Phrase 

Upon installation, Safery didn’t call the command-and-control server to transfer data. Instead, as Socket’s Threat Research Team discovered, It encoded the seed phrase, the 12- or 24-word recovery phrase used to restore a wallet on its native blockchain in synthetic Sui-style blockchain addresses. 

The extension then sent a very small number of SUI tokens (like 0.000001 SUI) to those manipulated addresses from wallets owned by the attacker. 

By observing these transactions on the Sui blockchain and decoding the recipient addresses, threat actors would be able to determine the user’s full seed phrase.

Socket’s reverse engineering protocol revealed that each word in the seed phrase would be translated to its index in a standard BIP-39 list and then packed into a hex string, padded and interpreted as a fake Sui address. 

This sidestepped classic network calls or suspicious-looking HTTP traffic, as the exfiltration “occurred” on the blockchain.

Why It Went on So Long: Failures in Chrome Store Vetting

Part of how Safery reached so high in the Web Store ranks has to do with how Chrome’s Extension marketplace is set up. 

With the store’s algorithm heaving in favour of install count, review velocity, and average rating rather than deep security vetting. Since Safery generated fake 5-star reviews so quickly, it started to gain traction. 

Its description was polished and its permissions appeared routine, allowing it to slip past Google’s more aggressive security checks.

Even after researchers raised an alarm about the threat, the removal wasn’t immediate. 

According to security teams, the fact that Safery’s activity did not include suspicious on-chain behavior but rather presence on-chain and no peculiar external network-related actions, had made conventional malware detection mechanisms less applicable.

How Users Were Warned and What They Can Do

Socket and several cybersecurity outlets raised red flags as soon as they discovered Safery’s behavior pattern. 

They encourage users to never input their seed phrases into unfamiliar, or unverified extensions. 

Whenever they do install a wallet extension, users should make sure to inspect the publisher’s reputation, see if there is an actual website or GitHub repository and scout reviews for patterns such as common generic praise.

If someone believes there is a chance that they have used Safery or any other similarly malicious extension, experts recommend uninstalling the extension at once, revoking all approvals (ERC-20 or elsewhere), and sweeping funds to a new wallet with a secure model of device. 

These steps will limit damage but any wallet touched by Safery is compromised.

Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui
Chrome Wallet Scam Exposed: Extension Steals Your Seed Using Sui

A Warning for the Crypto Ecosystem

This vulnerability that led to this chrome wallet scam runs deeper. Browser wallets themselves are fundamentally unsafe. Although they offer ease of use and access to DApps, they expose large attack surfaces. 

Mixing UI legitimacy with stealthy on-chain exfiltration allowed the Safery extension to evade conventional anti-malware security mechanisms.

Security researchers are demanding fixes. 

Suggestions include automatic flagging of extensions that request seed phrase input, better permissions checks, and for there to be a way of verifying publishers i.e. making sure that a wallet really is from a project whose source has been examined according to standards. 

For users, it’s a hard lesson: not every Chrome wallet is secure, and trust should be earned rather than freely given.

Conclusion

The Safery chrome wallet scam is among the most sophisticated crypto malware. By sneaking seed phrases into tiny-size Sui blockchain transactions, the attackers side-stepped conventional detection and constructed an invisible exfiltration channel. 

The Chrome Store hacker abused the trust in Chrome Store, had elevated itself from fake reviews and even utilized the blockchain itself to spill private data. 

The lesson here for wallet users is obvious: always scrutinize extensions, watch the blockchain traffic and approach seed phrase input with extreme caution.

Glossary

Seed Phrase (Mnemonic): List of 12 or 24 words that can be used as a backup to recover wallet and access funds.

Microtransaction: The smallest of blockchain transactions; in this case, sent to move data elsewhere.

BIP-39: A mnemonic seed phrase standard used by many crypto wallets.

Command-and-Control (C2): A server or infrastructure operated by attackers to which data that has been stolen are transmitted.

RPC (Remote Procedure Call): Protocol by which wallets communicate with blockchain nodes.

Frequently Asked Questions About Chrome Wallet Scam

How did the Safery extension go undetected?

Instead of transmitting data over HTTP, it encoded the secret into seemingly legit Sui blockchain transactions, bypassing common malware detection.

Did the extension impersonate a popular wallet?

No, Safery carved its own path. It wasn’t impersonating MetaMask or an existing brand, which could have made it easier to spot.

If someone used Safery can they get money back?

Recovery is hard if seed phrase were leaked. The best course of action is to transfer their funds to a different wallet with newly generated seed.

How do I know if a wallet extension is safe?

Look for developer reputation, active website or repo, good consistent reviews and whether the extension requests seed phrases in insecure contexts.

Will other blockchains be vulnerable to similar attacks?

Experts caution that this method could be mimicked with other public blockchains, not just Sui.

References

SC Media

The Hacker News

Cointelegraph

Cyberwarzone

Daily CyberSecurity

Malware Analysis

Advertising

For advertising inquiries, please email . [email protected] or Telegram

Is LINE NEXT Following Suit of Telegram? A New Initiative to Expedite Web3 Adoption in Asia

Why McGregor Slams U.S. Over Crypto Picks: “Why XRP, SOL, and ADA?”

Binance Surpasses $100 Trillion in Trading Volume Milestone

Ethereum’s $153M Inflow Sparks… Nothing. Here’s Why.

Meme Coins Roar Back to Life as Trump’s Tariff Pause Shakes Up Markets

TAGGED:Chrome StoreChrome Store VettingChrome Wallet Scamcrypto wallet hackCrypto Wallet SecuritySafery extensionSafery: Ethereum WalletSeed Phrase hackWallet Hack

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
ByJane Omada Apeh
Follow:
Omada is a dedicated crypto journalist with a passion for making the fast-paced world of digital assets understandable and engaging. With years of experience covering cryptocurrency and blockchain innovation, she offers readers more than just the headlines. She provides context, clarity, and depth. Her work spans everything from market trends and regulatory updates to emerging technologies and real-world use cases that are shaping the future of finance. Omada strives to bridge the gap between complex crypto concepts and everyday readers, ensuring that both seasoned investors and curious newcomers can find value in her insights. Her mission is simply to inform, inspire, and keep her audience one step ahead in the ever-evolving crypto universe.
ByMuhammad Saad
Follow:
Muhammad Saad serves as an editor at Deythere, dedicated to delivering content that is sharp, insightful, and reader-friendly. With extensive experience in digital journalism, Saad focuses on connecting the world of cryptocurrency, blockchain, and finance with everyday audiences. From market insights and breaking stories to analytical features and predictions, he ensures every article is factual, engaging, and easy to grasp.
Previous Article Polygon Partnerships Polygon Partnerships Bring Big Institutions Onboard in November 2025
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Bitcoinbitcoin
$85,974.00
24h Volume
$69,463,971,927
Market Cap
$1,715,683,048,736
24h Low/High
$85,701.00 / $87,995.00
24h ▼0.84%
7d ▼9.77%
Subscribe to our newslettern

Get Newest Articles Instantly!

Popular News
AI regulations
AI Regulations Discussed at United Nations Conference
gorilla
Gorilla Sudden Ascent in the Crypto Market
dog runes 1
BNB Bull Run Unpacking the Recent Surge in Market Valuation
bitcoin
Bitcoin Surges Amidst Optimistic Market Conditions
trump coin
Super Trump Coin Soars Analyzing Its Recent Surge in the Crypto Market
mogg coin
Mog Coin Surges Unpacking Its Rise and Future Prospects in Crypto
pendle coin
Pendle Soars Analyzing Its Recent Price Surge and Market Dynamics
stack coin
Stacks (STX) Sees Significant Gains with an 11.77% Surge in the Crypto Market

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Deythere

DT News influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Menu

  • Home
  • News
© DT News. All Rights Reserved.
Banner 1
Banner 2
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

  • English