Glossary entry
Malicious Browser Extension
Wallets & SecurityAn extension with broad site permissions can rewrite addresses, read what you type and forge wallet prompts — including after an update.
Definition
A browser extension runs inside the browser with the permissions granted at install, and an extension able to read and change data on all sites can see everything a page shows and alter what it shows. That is enough to rewrite a payment address as a page renders it, capture what is typed into a wallet or exchange form, read session cookies, or inject a prompt that looks like it came from a wallet. The extension need not have been malicious when installed: a popular one can be sold or its developer account compromised, and the update arrives silently under a name the user already trusted. Reputation and install counts therefore describe the past rather than the code currently running. The practical limits are to keep few extensions, grant the narrowest site access an extension offers, and keep the browser that holds significant funds separate from the one used for everything else.
Next