SlowMist Warns of Fake TronLink Chrome Extension Phishing Attack

CryptoFrontier
TRX0.49%

Cryptocurrency security company SlowMist has issued a security alert warning of a high-risk phishing attack targeting TRON (TRX) wallet users, according to a press release from the company. Attackers created a malicious Chrome extension that mimics the official TronLink wallet, using sophisticated spoofing techniques to deceive users into installation. The fake extension steals wallet credentials and transmits them to attackers in real-time.

Attack Method

The malicious extension employs Unicode bidirectional control characters and similar Cyrillic letters to spoof the extension’s name, making it nearly identical to the legitimate TronLink wallet extension. The fake extension is listed in the Chrome Web Store and leverages the high download numbers and positive reviews of the official version to appear trustworthy to ordinary users, making detection extremely difficult.

Attack Chain

Once installed, the malicious extension uploads a phishing page via a remote server. This page perfectly replicates the official TronLink web wallet interface. When victims log into their TRON wallet through the fake interface, the extension captures their private keys, keystore files, and passwords. This stolen information is transmitted to the attackers in real-time through a Telegram bot, completing the credential theft chain.

Recommended Actions for TRON Users

SlowMist recommends the following protective measures:

  1. Immediately check and remove any suspicious extensions from unknown sources from your browser
  2. Clear your browser’s local storage data to remove any cached credentials
  3. Be aware of unusual network requests that may indicate ongoing phishing attempts
  4. If wallet information has been compromised, immediately create a new wallet and move all assets to a secure address

The security firm emphasizes that users should only download wallet extensions from official sources and verify URLs carefully before entering sensitive information.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
TheFeelingOfEthInTheSeaBreezevip
· 05-11 19:24
Forwarded to group members: such high-quality imitation extensions can even deceive veteran users. Be sure to verify the developer's identity and store ratings before installation.
View OriginalReply0
OwlAuthorizationMonitorvip
· 05-11 19:21
Chrome extensions are hard to distinguish real from fake. This time, the TronLink imitation is really aggressive, so I need to remind friends who use TRX not to click on suspicious links.
View OriginalReply0
PatinaTradingBellvip
· 05-11 19:13
SlowMist's warnings are timely, but user education is fundamental; too many people just look at the icon and dare to install plugins.
View OriginalReply0
GateUser-e3701961vip
· 05-11 19:01
Once again, it's Chrome extension phishing. Where exactly is the security boundary of browser wallets?
View OriginalReply0