Case · DiggingBeagle record

Silent Swap injected a Chromium extension that replaced crypto wallet addresses

McAfee Labs identified an active crypto-clipper campaign using unsigned installers to deploy a malicious Chromium extension masquerading as Google Notes. The extension monitored copied cryptocurrency addresses and replaced intended destinations with attacker-controlled addresses. The installer also manipulated protected Chromium browser settings and used blockchain-resolved command-and-control infrastructure.

Evidence boundary

Observed malware campaign targeting Chromium-family browsers and cryptocurrency transactions. McAfee analyzed installers and extension behavior and reconstructed the attacker backend protocol. Aggregate victim count and total stolen value remain unknown.

Not yet assessed. The record's Claims and Sources remain available; missing grades do not mean low impact.Assessment method

30-second account

Mechanism and trust boundary

Typed chronology

Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.

  1. Jun 30, 2026
    disclosure

    Public disclosure

Claims & evidence

3 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-SILENT-SWAP-DYNAMIC-WALLETSMcAfee's reconstructed backend testing found deterministic attacker-controlled replacement-address mappings for multiple cryptocurrencies, while the unknown total number of attacker wallets prevented a reliable estimate of aggregate stolen funds.supported

Basis: reported finding

Permanent Claim anchor
CLM-SILENT-SWAP-BROWSER-INJECTIONMcAfee found that the installer targeted Chromium-family browser profiles including Chrome, Edge, Opera and Brave, modified Preferences or Secure Preferences and attempted to update integrity-related values so the malicious extension would load.supported

Basis: reported finding

Permanent Claim anchor
CLM-SILENT-SWAP-ADDRESS-REPLACEMENTThe malicious extension monitored cryptocurrency addresses copied by the user and replaced matching destination addresses with attacker-controlled addresses before the victim pasted them.supported

Basis: reported finding

Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • The total number of victims is not established by the cited Source.
  • The total cryptocurrency stolen cannot be reliably estimated because the campaign dynamically assigns many attacker-controlled wallet addresses.
  • Balances observed in individual attacker wallets cannot be treated as the campaign's aggregate realized loss.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 50

Cite this record

DiggingBeagle. “Silent Swap injected a Chromium extension that replaced crypto wallet addresses.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Jun 30, 2026. https://diggingbeagle.com/cases/silent-swap-injected-a-chromium-extension-that-replaced-crypto-wallet-addresses/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology