Blog
Wallet Chrome Extensions Caught Stealing User's Funds

Wallet Chrome Extensions Caught Stealing User's Funds

Reviewed by
Revealed: A chain of Wallet Chrome extensions that are malicious and steal users’ data.
Table of Contents
Revealed: A chain of Wallet Chrome extensions that are malicious and steal users’ data.

Key Takeaways

__A Google Chrome extension named "Shitcoin Wallet" was caught stealing passwords and private keys. __

The "Shitcoin Wallet" (Pardon our French, but that's the name of the app. The definition of "Shitcoin" is, in fact, a cryptocurrency of little value) is an app which allows users to manage ETH coins and ERC20 tokens from within their browser. Additionally to the Chrome extension, users can also download a desktop app and control their funds from outside the browser's more endangered environment.


shitcoin-wallet


The Chrome extension, which was launched on December 9th, 2019, has already been removed; however, the website remains live where the Windows app is still available to download.

The extension was removed after the finding that it actually contained malicious code, which could cause the following:

  • Funds managed directly from the extension are at risk. The extension sends the private information of all wallets created or managed through its interface to a third-party website.
  • The extension implements malicious code when users browse to popular cryptocurrency management websites, steals credentials and private keys, and sends them to the same third-party site.


shitcoin


While Guardio blocks malicious sites like this, our research team had a closer look at this site and wanted to share certain things that you should always pay attention to:

  • Grammar/ Spelling: The title should be "how it work__s__" or How does it work. Additionally, "ther're" is used for casual writing/texting, and is not something one would expect from a respectful company.


shitcoin1


  • False links: Not only does the text: "which I will discuss further" seem a little odd placed on a company page, but this text cube doesn't even lead anywhere.


shitcoin2


  • Suspicious Social Media: When taking a close look at Shitcoin's Twitter account, the followers look like bots. This can be detected by the date they joined Twitter: December 2019 (when the app was launched), and the only content on their account is of the "Shitcoin" app.


twitter fake


But wait, there's more.

Guardio's research team detected another extension by the same people that were exposed before "Shitcoin" called "SAFU Wallet". Hackers like this tend to open new apps with the same code and different appearances every time one gets closed. This means that there will most likely be another attempt for a similar app.

Rest assured that if you use Guardio as your browsing protection, we have removed this extension automatically and will warn you from such malicious apps.

{{component-cta-custom}}

CMS-based CTA:
Clean up your browser and prevent future scams
Protect yourself from malicious apps & other scams, begin with a free scan.
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

No items found.
Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now