Nineteen Chrome and Edge add-ons turned malicious after users installed them, stealing exchange sessions and phishing Ledger and Trezor recovery phrases.
GLOBAL — Security researchers have exposed a campaign that goes after bitcoin holders where they are softest: the browser. The security firm Socket, which named the operation “Superior” after tags in the malicious code, tracked a cluster of 19 Chrome and Edge extensions built to drain wallets, steal exchange logins and hijack the buttons users click to move money.
The trick is patience. Of the 19 extensions, 14 were created by the attacker and five were bought from their original developers — tools that already carried real functionality and trust. The operators shipped a clean version first, let downloads and reviews accumulate, then pushed the malicious payload later through a routine background update. A user who installed a helpful little add-on months ago never reinstalled anything; the danger arrived on its own.
Once active, the malware harvests session cookies and bearer tokens from anyone logged into Coinbase, Binance, Kraken, OKX, KuCoin, MEXC or Bybit — letting the attacker act as the victim without ever needing a password or a two-factor code. It rewrites a page’s real “Connect Wallet” and “Swap” buttons to route approvals to the thief. And on trezor.io and ledger.com it throws up pixel-perfect full-page overlays that beg the user to type in their recovery phrase — the 12 or 24 words that are the master key to a hardware wallet.
To pull this off it strips Content-Security-Policy headers, a browser protection that limits which scripts a page may run, using an extension permission called declarativeNetRequest. Because the theft happens inside the browser, on the user’s own machine, it sidesteps the very defenses bitcoiners are told to rely on: two-factor authentication and, in the seed-phrase case, the hardware wallet itself.
The base layer wasn’t touched. The two places a normal person keeps bitcoin — an exchange login and a hardware wallet — were.
Nothing here is a flaw in Bitcoin. The protocol did what it always does; the attack targets the human interface around it. That distinction is the whole of self-custody. A hardware wallet protects you only if you refuse to enter its recovery phrase anywhere but the device — no website, no popup, no “validation” screen, ever has a legitimate reason to ask. An exchange balance, meanwhile, is only as safe as the browser session it lives behind.
The practical defenses are unglamorous and effective: keep the seed phrase offline and never type it into a screen; verify every send on the hardware wallet’s own display; run as few extensions as possible and treat any that suddenly asks for broad permissions as suspect; and for real savings, use a dedicated browser or machine. The attackers are getting more sophisticated. The rules for not getting drained have not changed.
Why it matters: bitcoin’s cryptography holds; the weak point is the browser in front of it — and this campaign is a reminder to keep your keys off the screen.
The “Superior” naming, the 19-extension count (14 created, 5 purchased), the clean-then-malicious update tactic, the targeted exchanges, the Connect Wallet/Swap hijacking, CSP-header stripping via declarativeNetRequest, and the Ledger/Trezor seed-phrase phishing overlays are per the Socket research and the coverage cited. The campaign targets multiple assets; this piece covers the bitcoin-relevant exposure. Informational only — not security or financial advice; verify guidance independently.
Free. Five minutes. No hype.
Subscribe free