Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

A new study has uncovered disturbing vulnerabilities in popular cryptocurrency wallet extensions, putting users’ sensitive information at risk of exposure and exploitation. Researchers analyzed 85 crypto wallet browser extensions, discovering that many leak users’ addresses and engage in cross-site tracking, potentially compromising the security of millions of people worldwide.

The study, conducted by a team of cybersecurity experts, focused on examining the source code of various crypto wallet extensions available for download from the Chrome Web Store. What they found was alarming: over 70% of the analyzed extensions leaked users’ Ethereum addresses in plain text, allowing third-party scripts to access this sensitive information. Furthermore, nearly 60% of these extensions were found to be engaging in cross-site tracking, monitoring users’ browsing habits across multiple websites.

These findings are concerning for several reasons. First and foremost, cryptocurrency wallet addresses are unique identifiers that can be used to track a user’s online activities, making it easier for malicious actors to target them with phishing attacks or other forms of exploitation. Cross-site tracking, meanwhile, allows advertisers and third-party companies to collect users’ browsing data without their consent, potentially infringing on their right to online privacy.

The researchers noted that many of these vulnerabilities were caused by the extensions’ reliance on outdated libraries and lack of proper input validation. This is a common issue in software development, where developers often fail to keep up with the latest security patches and best practices, leaving users exposed to known weaknesses. The study’s authors emphasized the need for browser extension developers to prioritize security when designing their products.

The findings also underscore the importance of user education in cybersecurity. While cryptocurrency wallet extensions are designed to provide a convenient way for users to interact with blockchain-based services, they can also pose significant risks if not used responsibly. By choosing reputable and well-maintained extensions, using strong passwords and enabling two-factor authentication, and regularly monitoring their online accounts for suspicious activity, users can minimize the risk of falling victim to these types of attacks.

Ultimately, this study serves as a reminder that even seemingly innocuous software applications can pose significant security risks if not properly designed and maintained. By taking steps to educate ourselves about the potential dangers lurking in our browsers and choosing reputable extensions, we can all play a role in protecting our online identities and financial information.


Source: The Hacker News — 2026-07-14