TechFlow, November 14 — According to disclosure from the GoPlus Chinese community, a malicious Chrome extension named "Safery: Ethereum Wallet" has been found stealing user assets. The extension, released on November 12, 2024, pretends to be a simple and secure Ethereum wallet but contains a built-in backdoor.
The attack method is highly covert: the malicious extension encodes users' mnemonic phrases into Sui addresses and steals them by broadcasting tiny transactions through attacker-controlled Sui wallets. The attacker's email is kifagusertyna@gmail[.]com.
As of now, the malicious extension has not been removed from the Chrome Web Store.





