• Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated on 06/17/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Legitimate Chrome extension hijacked to drain crypto wallets in 'ClickFix' attack targeting 7,000 users

Legitimate Chrome extension hijacked to drain crypto wallets in ‘ClickFix’ attack targeting 7,000 users

03/03/2026
Hong Kong built a crypto regime that only banks and Beijing can love

Hong Kong to approve first stablecoins in March, cementing bid for regulated crypto leadership

03/03/2026
Ethiopia crypto regulation tightens with birr-paired P2P ban

Ethiopia bans birr-crypto P2P trading without central bank approval

03/03/2026
  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated on 06/17/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Legitimate Chrome extension hijacked to drain crypto wallets in 'ClickFix' attack targeting 7,000 users

Legitimate Chrome extension hijacked to drain crypto wallets in ‘ClickFix’ attack targeting 7,000 users

03/03/2026
Hong Kong built a crypto regime that only banks and Beijing can love

Hong Kong to approve first stablecoins in March, cementing bid for regulated crypto leadership

03/03/2026
Ethiopia crypto regulation tightens with birr-paired P2P ban

Ethiopia bans birr-crypto P2P trading without central bank approval

03/03/2026
Tuesday, March 3, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Legitimate Chrome extension hijacked to drain crypto wallets in ‘ClickFix’ attack targeting 7,000 users

A compromised Chrome add-on leveraged social engineering and malware to siphon crypto assets from thousands of users worldwide.

by Joseph Samuel
3 hours ago
in Crypto News
Reading Time: 3 mins read
0
Legitimate Chrome extension hijacked to drain crypto wallets in 'ClickFix' attack targeting 7,000 users

Legitimate Chrome extension hijacked to drain crypto wallets in 'ClickFix' attack targeting 7,000 users

Share on FacebookShare on Twitter

A legitimate Chrome extension trusted by thousands of crypto users was hijacked in February 2026 to distribute malware targeting MetaMask, Phantom, and Coinbase Wallet. The attackers embedded code that harvests seed phrases, wallet credentials, and browser data through fake update pop-ups—a technique security researchers call ClickFix.

The extension, QuickLens Search Screen with Google Lens, was removed from the Chrome Web Store after it was found distributing malware and conducting so-called ClickFix attacks.

This attack is seen as a social engineering technique that coaxes users into executing harmful code on their own machines.

Originally a tool enabling in-browser Google Lens searches, QuickLens had amassed an estimated 7,000 users worldwide before its compromise in February 2026, according to analysis by security outlet BleepingComputer.

Threat actors took advantage of a change in the extension’s ownership in early February, pushing a new version containing malicious scripts that requested elevated permissions and systematically weakened browser security controls.

“The extension stripped critical security headers… allowing arbitrary JavaScript injection on every page load.” BleepingComputer analysis said, summarizing how the malware operated.

How ‘ClickFix’ and social engineering trick users

Unlike traditional malware that exploits software vulnerabilities, ClickFix relies heavily on deception and user interaction.

When unsuspecting users encountered fake prompts such as bogus Google Update pop-ups, the technique manipulated victims into copying and pasting attacker-supplied commands into their systems.

A joint report by cybersecurity researchers described how the compromised extension communicated with a command-and-control server to deliver malicious payloads.

This attack was targeted at a wide range of browser-based wallets, including MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare and others.

Stolen seed phrases and wallet credentials enabled attackers to drain funds and seize accounts.

“The ClickFix attack coerces users into executing attacker-supplied code under the pretense of a necessary browser update.” Threat analysis report on QuickLens campaign.

In addition to cryptographic key theft, the malware also scraped Gmail inboxes, logged sensitive form data, and harvested other credentials stored in the browser.

Broader trend: extension supply chain attacks rising

Security experts warn that the QuickLens incident is part of a growing trend of supply chain attacks targeting seemingly benign browser extensions and tools.

Because extensions run with high privileges in users’ browsers, they are attractive vectors for attackers aiming to bypass endpoint protections.

Recent threat reports have flagged similar social engineering techniques, including other ClickFix variants that manipulate fake CAPTCHA prompts and copy-paste operations to infect devices with credential stealers and crypto-targeting malware.

Microsoft’s threat intelligence teams have been tracking ClickFix and related campaigns since at least 2024, noting their expansion beyond crypto into broader enterprise and consumer environments.

Likewise, cybersecurity firm Unit42 documented the technique’s impact on sectors ranging from manufacturing and retail to government and energy.

Advice for crypto holders and browser users

Affected users are urged to immediately uninstall the QuickLens extension, run comprehensive malware scans, and reset passwords for any accounts accessed through the browser.

Experts also recommend transferring any remaining crypto holdings to new wallets not associated with the compromised environment.

Because the threat shows weaknesses in extension vetting and update mechanisms, security professionals advise limiting installations to essential, verified extensions, and regularly auditing permissions to detect suspicious activity.

As the digital asset ecosystem continues to attract financially motivated attackers, this incident serves as a stark reminder of the need for vigilance and layered security practices among crypto investors and general internet users alike.

Tags: 000 users affected7%browser malwareChrome extension hijackClickFix attackcrypto users targetedcrypto wallet draincybersecurity threatdigital asset theftendpoint securitymalicious updatePhishing campaignprivate key theftsupply chain attackwallet security breachweb3 security
Share196Tweet123
Joseph Samuel

Joseph Samuel

Samuel Joseph is a professional writer with experience creating clear, engaging, and well-researched crypto contents. He specializes in Crypto contents, educational articles, debate pieces, and informative reviews, with a strong ability to adapt tone to suit different audiences. With a passion for simplifying complex ideas and presenting them in a compelling way, he delivers content that informs, persuades, and connects with readers. Samuel is committed to accuracy, originality, and continuous improvement in his craft, making him a reliable voice in digital publishing.

  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
XRP community

Ripple CEO reassures community after SWIFT selects rival blockchain for pilot

02/10/2026
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated on 06/17/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Legitimate Chrome extension hijacked to drain crypto wallets in 'ClickFix' attack targeting 7,000 users

Legitimate Chrome extension hijacked to drain crypto wallets in ‘ClickFix’ attack targeting 7,000 users

03/03/2026
Hong Kong built a crypto regime that only banks and Beijing can love

Hong Kong to approve first stablecoins in March, cementing bid for regulated crypto leadership

03/03/2026
Ethiopia crypto regulation tightens with birr-paired P2P ban

Ethiopia bans birr-crypto P2P trading without central bank approval

03/03/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?