Skip to content
IntermediateTax and safety

Keeping browser extensions to a minimum

Author
CRYPTO PORT Editorial
Published
Updated
Reading time
5 min

In short

A browser extension can read and modify the pages you are looking at. On the browser you use for wallets, keep only what you need. Popular extensions have been sold on and turned malicious through a routine update.

Key points

  • 'Read and change all your data on all sites' means it sees what you see and what you type
  • Extensions auto-update — one that was safe at install can become something else
  • Fake wallet extensions do appear in stores; install only via the link on the official site
  • A separate browser or profile for wallet use contains the blast radius

Definition

Small programs added to a browser. Many hold permission to read and rewrite the pages you visit, which makes them a risk when you use a wallet in the same browser.

When you install an extension you are often asked to allow it to 'read and change all your data on all sites'. Take that literally: it can see your exchange screen, your wallet's signing prompt and the password you type. Ad blockers, translators, coupon finders, screenshot tools, themes — convenience is what you get in exchange for handing over that access, and it is worth being conscious of the trade.

The awkward part is automatic updates. An extension written by a conscientious developer can have its project sold to a third party, and the next update ships code that injects ads or exfiltrates data. You did nothing, yet one day the behaviour changes. 'It was safe when I installed it' is therefore not an argument.

Two practical measures. First, reduce the count: delete anything you have not used in three months, and where the permission settings allow 'on specific sites only', narrow it. Second, separate: use a distinct browser profile, or a different browser entirely, for wallet work, with no extensions there beyond the wallet itself. Then whatever lives in your everyday browser never reaches a signing prompt.

Watch for fakes of the wallet extension itself. Counterfeits with near-identical names and icons have appeared in official stores. Do not install the top search result; install from the link published on the wallet's own site, which you reached from your own bookmark. After the fact, what justifies your trust is the path you took, not the review count.

Watch out for

  • · Install a wallet extension only from the link on its official site
  • · Delete extensions you do not use — disabling alone can leave permissions in place
  • · If an extension asks you to enter a seed phrase, that extension is a fake

Frequently asked questions

  • Does a hardware wallet make extensions harmless?

    The key never leaves the device, so the key itself is protected. But swapping the destination address on screen still works as an attack, which is why you must read the address and amount on the hardware wallet's own display before approving.

Read next

Crypto quizzes

Answer a few questions and get your result instantly.

Start