A concise reconstruction has not been recorded.
Inspect the ClaimsCase · DiggingBeagle record
Silent Swap injected a Chromium extension that replaced crypto wallet addresses
McAfee Labs identified an active crypto-clipper campaign using unsigned installers to deploy a malicious Chromium extension masquerading as Google Notes. The extension monitored copied cryptocurrency addresses and replaced intended destinations with attacker-controlled addresses. The installer also manipulated protected Chromium browser settings and used blockchain-resolved command-and-control infrastructure.
Observed malware campaign targeting Chromium-family browsers and cryptocurrency transactions. McAfee analyzed installers and extension behavior and reconstructed the attacker backend protocol. Aggregate victim count and total stolen value remain unknown.
30-second account
No separate implication has been established in the canonical account.
Read the stated implicationsThe total number of victims is not established by the cited Source. The total cryptocurrency stolen cannot be reliably estimated because the campaign dynamically assigns many attacker-controlled wallet addresses. Balances observed in individual attacker wallets cannot be treated as the campaign's aggregate realized loss.
Inspect limits and uncertaintyFull canonical reconstruction
Mechanism and trust boundary
Typed chronology
Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.
- Jun 30, 2026disclosure
Public disclosure
Claims & evidence
3 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.
CLM-SILENT-SWAP-DYNAMIC-WALLETSMcAfee's reconstructed backend testing found deterministic attacker-controlled replacement-address mappings for multiple cryptocurrencies, while the unknown total number of attacker wallets prevented a reliable estimate of aggregate stolen funds.supported
Basis: reported finding
- supportsSilent Swap: A Crypto Clipper Extension Campaignprimary disclosure
Wallet Substitution Logic and Analyzing Attacker Crypto Wallets, discussion of per-address mappings and loss-estimation limitation
CLM-SILENT-SWAP-BROWSER-INJECTIONMcAfee found that the installer targeted Chromium-family browser profiles including Chrome, Edge, Opera and Brave, modified Preferences or Secure Preferences and attempted to update integrity-related values so the malicious extension would load.supported
Basis: reported finding
- supportsSilent Swap: A Crypto Clipper Extension Campaignprimary disclosure
Installer analysis around Figures 25-29 describing Chrome, Edge, Opera and Brave profile modification and Secure Preferences tampering
CLM-SILENT-SWAP-ADDRESS-REPLACEMENTThe malicious extension monitored cryptocurrency addresses copied by the user and replaced matching destination addresses with attacker-controlled addresses before the victim pasted them.supported
Basis: reported finding
- supportsSilent Swap: A Crypto Clipper Extension Campaignprimary disclosure
Wallet Substitution Logic, paragraphs describing copy-event interception and backend-provided replacement addresses
Implications within the documented scope
Controls and mitigations
No controls or verified fix are recorded.
Unknowns and contradictions
- The total number of victims is not established by the cited Source.
- The total cryptocurrency stolen cannot be reliably estimated because the campaign dynamically assigns many attacker-controlled wallet addresses.
- Balances observed in individual attacker wallets cannot be treated as the campaign's aggregate realized loss.
Sources and citation
Material revision history
- Sep 25, 2026 · Published version · first publication · revision 50
Cite this record
DiggingBeagle. “Silent Swap injected a Chromium extension that replaced crypto wallet addresses.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Jun 30, 2026. https://diggingbeagle.com/cases/silent-swap-injected-a-chromium-extension-that-replaced-crypto-wallet-addresses/
Citation guidance