{"id":221697,"date":"2024-04-08T16:54:55","date_gmt":"2024-04-08T16:54:55","guid":{"rendered":"https:\/\/michigandigitalnews.com\/index.php\/2024\/04\/08\/trader-loses-800k-in-crypto-to-malicious-google-chrome-extension\/"},"modified":"2025-06-25T17:19:04","modified_gmt":"2025-06-25T17:19:04","slug":"trader-loses-800k-in-crypto-to-malicious-google-chrome-extension","status":"publish","type":"post","link":"https:\/\/michigandigitalnews.com\/index.php\/2024\/04\/08\/trader-loses-800k-in-crypto-to-malicious-google-chrome-extension\/","title":{"rendered":"Trader loses $800k in crypto to malicious Google Chrome extension"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/readwrite.com\/wp-content\/uploads\/2024\/04\/6RqQYcimSzmIwkdlxmXEgg-900x561.jpg\" \/><\/p>\n<div>\n<p>A Cryptocurrency investor has alleged that two \u2018weird extensions\u2019 have drained $800,000 from multiple of his wallet apps.<\/p>\n<p>The <a href=\"https:\/\/readwrite.com\/security-cyber-agency-warns-this-wordpress-widget-might-leak-data\/\">trading and crypto<\/a> user, who goes by the name \u2018sell9000\u2019 on X, has taken to the social media platform to speculate about how this happened.<\/p>\n<p>He says \u201cI suspect this was a Google Chrome compromise containing a possible keylogger targeting specific wallet extension apps\u2026\u201d<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Just realized I got $500k drained from multiple wallet apps 46 hours ago<\/p>\n<p>Think I got extension attacked, with two suspicious extensions that appeared on my chrome browser<\/p>\n<p>does not feel good fam<\/p>\n<p>still investigating<\/p>\n<p>\u2014 Sell When Over | 9000.sei (@sell9000) <a href=\"https:\/\/twitter.com\/sell9000\/status\/1777158691214569636?ref_src=twsrc%5Etfw\">April 8, 2024<\/a><\/p>\n<\/blockquote>\n<p>A keylogger is a malicious application used by <a href=\"https:\/\/readwrite.com\/accounting-giant-deloitte-seeking-specialists-for-crypto-investigations\/\">cyber criminals<\/a> to record every action of a keystroke made by another user. That data can then be retrieved by the person operating the logging program.<\/p>\n<p>The user explained how he did a Google Chrome update a few weeks ago, but said that unusually \u201call my tabs were gone and extension logins had reset\u201d when the browser relaunched. This included his wallets which were now logged out of and required details to be re-added.<\/p>\n<p>He alleges that \u201cChrome was compromised in that unusual reboot event\u201d and said he found two extensions titled \u2018Sync test beta\u2019 and \u2018Simple Game.\u2019<\/p>\n<p>The hackers have reportedly sent the funds to two exchanges, the Singapore-based MEXC exchange and the Cayman Islands-headquartered Gate.io.<\/p>\n<h2><b>\u201cA $800k costly mistake\u201d<\/b><\/h2>\n<p>In one of the latest updates, Sell9000 asks for further assistance and reports it\u2019s an ongoing issue.<\/p>\n<p>While the X user isn\u2019t yet sure how the extensions got onto Chrome and what the attack vector is, they say they can confirm that \u2018Sync test BETA (colorful)\u2019 is a keylogger. The other one \u2018Simple Game\u2019 is described as checking if tabs are updated, open, closed, and refreshed.<\/p>\n<p>Sell9000 chalks up the incident as being \u201ca $800k costly mistake\u201d and says \u201cThe lesson is if anything seems off such as that it prompts you to input a seed, then wipe the whole PC first.<\/p>\n<p>\u201cMy guard went down because the updated happened to be when Chrome made a significant update (where now you have to select a user and the[n] sign in with Google UI changed) so I thought that was what caused the extensions to reset and me to lose all my tabs.\u201d<\/p>\n<p><strong><em>Featured Image: Photo by <a href=\"https:\/\/unsplash.com\/@firmbee?utm_content=creditCopyText&amp;utm_medium=referral&amp;utm_source=unsplash\">Firmbee.com<\/a> on <a href=\"https:\/\/unsplash.com\/photos\/person-using-black-laptop-computer-eMemmpUojlw?utm_content=creditCopyText&amp;utm_medium=referral&amp;utm_source=unsplash\">Unsplash<\/a><\/em><\/strong><\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/readwrite.com\/trader-loses-800k-in-crypto-to-malicious-google-chrome-extension\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] A Cryptocurrency investor has alleged that two \u2018weird extensions\u2019 have drained $800,000 from multiple of his wallet apps. The trading and crypto user, who<\/p>\n","protected":false},"author":1,"featured_media":221698,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[152],"tags":[],"_links":{"self":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/221697"}],"collection":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/comments?post=221697"}],"version-history":[{"count":1,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/221697\/revisions"}],"predecessor-version":[{"id":329859,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/221697\/revisions\/329859"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media\/221698"}],"wp:attachment":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media?parent=221697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/categories?post=221697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/tags?post=221697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}