Risky Bulletin Newsletter
February 07, 2025
Risky Bulletin: Supply chain attack at AdsPower browser platform
Presented by
![Catalin Cimpanu](/static/img/catalin-cimpanu.jpg)
News Editor
A threat actor has compromised the AdsPower browser platform and injected malicious code that modified third-party crypto wallet extensions and stole user funds.
The breach took place on January 21 and went undetected for three days before the company removed the code and forcibly uninstalled all the targeted extensions from users' browsers.
According to SlowMist founder Yu Xian, the code worked as a backdoor that extracted mnemonic recovery phrases and private keys from the wallet extension and sent them to an attacker's server.