A fake Chrome extension empties a €100 wallet

A fake plugin posing as the official wallet was enough to lose just over €100. Google Play only removed the app after the victim reported it.

English · Original discussion in Spanish · Published

A fake Chrome extension empties a €100 wallet
The wallet that empties with one click on the wrong extension

The purchase wouldn't go through. The token portal didn't recognise the browser wallet and pointed to a link to install 'the' extension. Anyone who trinc it handed their keys to a plugin posing as the official one and watched the funds vanish in an instant: just over a hundred euros gone, with no hack, no cracked password and no technical drama. It's embeleco digital, the same old kind, but disguised as the tool people use every day. The victim tells it straight: he used one of the most common software wallets, the kind meant for paying rather than hoarding, and rarely kept more than a couple of hundred euros in it.

How they steal your wallet with a fake Chrome plugin

The trap is set in a chain. OpenSea, the main NFT marketplace, doesn't work with the installed wallet and directs you to the URL to download its own. That's where the casting error begins: the victim searched Google Play for a browser plugin, found one advertised as the official Chrome version and, with 'a ton of little stars' backing it, handed over the keys.

The fine detail is in the identifier. The legitimate extension responds to a specific string —nkbihfbeogaeaoehlefnkodbefgpgknn— and it only takes for that code to point, 'by mistake', to another site for the clone to slip in with an identical look. The lingering question is whether the link served by platforms can be diverted to that impersonator without anyone detecting it.

The institutional response was brief. Google Play removed the app and thanked the tip-off; the store argues it can't behave 'like the Gestapo' with every developer. The wallet, for its part, insists the blame lies with anyone who didn't inspect it closely. A hundred euros of damage and the feeling that there's no one on the other end of the phone.

Credit card versus cryptocurrencies: the comparison that makes people uneasy

The most painful argument isn't technical. With a card there's insurance, no fees, you barely pay currency conversion, transactions are reversible and the scammer is pursued through incivil proceedings. With a wallet, none of that. Maybe between the tax office and the bank you save some of what the exchange, intermediaries and mining costs take, but no one will defend you if you're robbed, and no one will bother to make it difficult.

From there comes the most uncomfortable conclusion: the lack of control over cryptocurrencies is cheaper for the robber than for the payer. The person saying it is not suspected of technophobia —he handles several wallets and has used them to buy all sorts of things— and admits that today he prefers any other payment method, including the shady portals that already accept other forms.

You are your own bank, and the mistake is yours

The industry's reply comes without anaesthesia. Here there are no refunds, transactions are final and no one hires you the insurance a bank does sign. If you do without the intermediary, you also do without its safety net. That's what the old warning sums up: you come to crypto having done your crying at home.

With that starting point come the first-year protocols: hardware wallet, air-gapped computer, zero clicks on ads and no extension that doesn't link to the project's official website. Those who get stung, they say, asked for it. The defence is logical and also biased: it demands from the individual a paranoia no other payment method asks for and turns the victim into the person responsible for the robbery.

From €100 to $2,500: the hole isn't one size

The cases pile up. A wallet drained of $2,500 by a contract accepted more than 120 days earlier and never revoked. An account closed on an exchange right after converting the funds into real money. Robberies from connecting through TOR. And just over a hundred euros lost when buying SIM cards from a seller with good references.

The question also looms whether any private company can track the scammer for a fee paid in bitcoins. No one offers a convincing example. The repeated sarracena: security is built beforehand, not afterwards; once the money leaves, it doesn't come back.

Asking for protection: is that asking for control?

Here the issue takes on a political tinge. For part of the public, demanding regulation and protection amounts to calling for more state, and anything that sounds like protection is read as a step towards control. The victim's response is that a democrat can want rules without wanting a dictatorship, and that the absence of law protects no one except those who break it.

Meanwhile, the industry itself moves where it suits it: even the big exchange platforms share data with Hacienda (Spain's tax agency). The lawless paradise ends where fiscal interest begins, not where the interest of the user whose wallet is emptied begins.

Then there's the detail that throws you off. The extension that stole the keys wasn't hidden in a sordid corner: it was two clicks away, in the world's most used app store, with its official-looking name and its five stars. When the victim reported it, the app disappeared from the store. The money didn't.

Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication. Read the full discussion (102 replies).

More summaries

All summaries in English →

Back