The “Fake Extension” Attack
Target: Chrome/Brave Users
⚠️ The Incident: A malicious browser extension mimicking the popular security tool “Revoke.cash” has appeared on the Chrome Web Store today. It is being promoted via Google Ads that appear above the real search results.
☠️ The Attack:
- The Trap: Users search for “Revoke cash” to check their wallet security.
- The Download: They install the fake extension (which uses the exact same logo).
- The Drain: Instead of “revoking” permissions, the extension asks for your seed phrase to “scan for vulnerabilities.”
Result: It drains the wallet instantly.
🛡️ ShieldGuard Rule:
- Never search for extensions. Always click the official link from the project’s Twitter bio or website.
- Red Flag: No security tool needs your Seed Phrase to “scan” anything.