Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Overview
A recent study by researchers at KU Leuven examined 85 popular crypto wallet extensions and discovered that many of them leak sensitive information, allowing for user tracking. The way these wallets communicate with websites and blockchain servers can inadvertently link different wallet addresses belonging to the same user, making it easier for outsiders to track their online activities. This poses a significant risk to user privacy, particularly for those who rely on these wallets for cryptocurrency transactions. The findings raise concerns about the security measures in place for these extensions and highlight the need for better user protection against potential tracking and data leaks.
Key Takeaways
- Affected Systems: 85 crypto wallet browser extensions
- Action Required: Users should review their wallet extensions for privacy features, consider using wallets with better security practices, and stay informed about updates from wallet developers.
- Timeline: Newly disclosed
Original Article Summary
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separate addresses together and let outsiders follow them from site to site. And on a site that already holds a name or
Impact
85 crypto wallet browser extensions
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should review their wallet extensions for privacy features, consider using wallets with better security practices, and stay informed about updates from wallet developers.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.