Silent Swap crypto clipper uses fake Google Notes extension to steal wallet addresses

Attackers are using a fake browser extension to steal crypto. McAfee Labs calls the campaign Silent Swap — and it works by replacing wallet addresses the moment you copy one.

Here’s the setup. You download what looks like a normal installer. It’s unsigned, but it runs. Behind the scenes, it scans for Chromium-based browsers — Chrome, Edge, Brave, Vivaldi. It kills the browser process, then injects a malicious extension disguised as a harmless “Google Notes” tool.

The extension asks for clipboard permissions. You grant them. Now every wallet address you copy gets redirected to an attacker-controlled address. On the blockchain, that money’s gone for good.

McAfee says the attackers use a technique called EtherHiding — storing command-and-control server details in a smart contract. Update the contract, and the malware points to a new server. No need to redeploy anything.

The extension even enables developer mode automatically in Brave and Opera to bypass browser protections. After installation, the installer deletes itself. No trace left.

Each wallet address type is mapped to a unique attacker address on the server side — Bitcoin, Ethereum, Bitcoin Cash, Ripple, Dash all get unique replacements. Solana addresses all go to one wallet. At the time of writing, that Solana address held $1,902.45.

Victims are global, with the highest concentration in India. The US, Brazil, Indonesia, and Spain are also heavily affected.

Separately, Socket reported two more malicious browser extensions — both called “VPN Go: Free VPN” — that also steal clipboard data. One was on the Chrome Web Store. The other was on Firefox Add-ons.

References