Cryptocurrency security company SlowMist has issued a security alert warning of a high-risk phishing attack targeting TRON (TRX) wallet users, according to a press release from the company. Attackers created a malicious Chrome extension that mimics the official TronLink wallet, using sophisticated spoofing techniques to deceive users into installation. The fake extension steals wallet credentials and transmits them to attackers in real-time.
The malicious extension employs Unicode bidirectional control characters and similar Cyrillic letters to spoof the extension’s name, making it nearly identical to the legitimate TronLink wallet extension. The fake extension is listed in the Chrome Web Store and leverages the high download numbers and positive reviews of the official version to appear trustworthy to ordinary users, making detection extremely difficult.
Once installed, the malicious extension uploads a phishing page via a remote server. This page perfectly replicates the official TronLink web wallet interface. When victims log into their TRON wallet through the fake interface, the extension captures their private keys, keystore files, and passwords. This stolen information is transmitted to the attackers in real-time through a Telegram bot, completing the credential theft chain.
SlowMist recommends the following protective measures:
The security firm emphasizes that users should only download wallet extensions from official sources and verify URLs carefully before entering sensitive information.
Related News
Crypto firms adopt “algorithm-upgraded” quantum-safe wallets, with multiple companies rolling them out to upgrade before the Bitcoin protocol.
Microsoft: Deployed ClickFix on a fake macOS troubleshooting page to steal crypto wallet keys
Crypto Wrench Attacks Surge 41% in 2026, Targeting Family Members
Payward Applies for OCC National Trust Company Charter
Crypto Wrench Attacks Rise 41% in 2026, Targeting Family Members