FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
Auditing Browser Extensions That Touch Your Crypto: A Practical Toolkit After ShieldGuard and Coruna
How-ToWeb Development

Auditing Browser Extensions That Touch Your Crypto: A Practical Toolkit After ShieldGuard and Coruna

via Dev.to JavaScriptohmygod5h ago

In the past two weeks, two separate campaigns reminded us that your wallet's biggest attack surface isn't the smart contract — it's the browser extension sitting three pixels away from your seed phrase. ShieldGuard , dismantled by Okta Threat Intelligence in March 2026, posed as a wallet-protection extension while silently harvesting addresses, scraping full HTML from Binance, Coinbase, and MetaMask post-login, and executing remote code via a C2 server. It bypassed Chrome's Manifest V3 restrictions using a custom JavaScript interpreter inside a closed Shadow DOM. Meanwhile, Google's Threat Intelligence Group disclosed Coruna (aka CryptoWaters), an iOS exploit kit that lures users to fake exchange frontends to extract wallet seed phrases — but its distribution chain relied heavily on malicious browser extensions as the initial pivot. And just days ago, CVE-2026-3928 proved that Manifest V3's permission model still allows UI spoofing via crafted extensions — the exact vector that makes p

Continue reading on Dev.to JavaScript

Opens in a new tab

Read Full Article
5 views

Related Articles

How To Apply Global Filters With EF Core Query Filters
How-To

How To Apply Global Filters With EF Core Query Filters

Medium Programming • 5h ago

How To Track Entity Changes With EF Core | Audit Logging
How-To

How To Track Entity Changes With EF Core | Audit Logging

Medium Programming • 5h ago

For Amazon's Fire Phone to succeed, it'll need to fix its app store problem first
How-To

For Amazon's Fire Phone to succeed, it'll need to fix its app store problem first

ZDNet • 5h ago

How to share your location on Android quickly: 5 easy ways - including by text
How-To

How to share your location on Android quickly: 5 easy ways - including by text

ZDNet • 6h ago

How-To

3 Mistakes Beginner Developers Make Every Year

Medium Programming • 7h ago

Discover More Articles