Scan to download
BTC $81,093.03 +0.40%
ETH $2,337.64 +0.54%
BNB $653.74 +0.56%
XRP $1.45 +1.79%
SOL $95.46 +1.78%
TRX $0.3507 +0.58%
DOGE $0.1101 +1.60%
ADA $0.2803 +3.30%
BCH $450.97 -0.62%
LINK $10.64 +1.50%
HYPE $42.06 -1.68%
AAVE $101.70 +5.52%
SUI $1.27 +11.96%
XLM $0.1676 +3.36%
ZEC $569.94 -4.85%
BTC $81,093.03 +0.40%
ETH $2,337.64 +0.54%
BNB $653.74 +0.56%
XRP $1.45 +1.79%
SOL $95.46 +1.78%
TRX $0.3507 +0.58%
DOGE $0.1101 +1.60%
ADA $0.2803 +3.30%
BCH $450.97 -0.62%
LINK $10.64 +1.50%
HYPE $42.06 -1.68%
AAVE $101.70 +5.52%
SUI $1.27 +11.96%
XLM $0.1676 +3.36%
ZEC $569.94 -4.85%

Slow Fog: TRON users should be vigilant against phishing activities involving counterfeit TronLink Chrome extensions

2026-05-11 16:51:48
Collection

SlowMist has issued a security warning stating that a high-risk phishing activity targeting TRON wallet users has been discovered. Attackers created a fake Chrome extension for the TronLink wallet, using Unicode bidirectional control characters and Cyrillic homographs to disguise the brand name. After installation, the extension loads a complete phishing page through a remote iframe, forming a "shell-core separation" credential theft chain.

The malicious extension name uses homographs for disguise, and its Chrome Store page inherits the high user count and positive reviews of the real extension, lowering the review threshold. There is very little local code, only loading remote pages, making static analysis nearly impossible to detect malicious behavior. The remote phishing page perfectly replicates the official TronLink web wallet interface, stealing mnemonic phrases, private keys, Keystore files, and passwords, and relaying them in real-time via a Telegram Bot.

Built-in anti-analysis features disable right-click, developer tools, drag-and-drop, and printing, and redirect based on the geographic and language settings of Russian users to evade detection. SlowMist recommends immediately uninstalling suspicious extensions, clearing local storage, checking for abnormal traffic, and if credentials have been entered, creating a new wallet and transferring assets immediately.

app_icon
ChainCatcher Building the Web3 world with innovations.