Tens of thousands of people have downloaded what they believed were useful AI tools for their browsers, only to give hackers a direct path into their most privateTens of thousands of people have downloaded what they believed were useful AI tools for their browsers, only to give hackers a direct path into their most private

Over 260,000 Chrome users hit by 30 fake AI extensions stealing browsing & email data

2026/02/13 03:20
4 min read

Tens of thousands of people have downloaded what they believed were useful AI tools for their browsers, only to give hackers a direct path into their most private online activity, including emails.

According to LayerX, over 260,000 Chrome users installed at least 30 malicious browser extensions masquerading as AI helpers. These claimed features, like chat support, email drafting, and content summaries, but in reality, they were quietly siphoning data in the background.

Trusted AI names used as cover

The timing was not random. With people eagerly adopting AI tools for both work and personal use, attackers seized on that excitement to slip in under the radar. The bogus extensions claimed ties to familiar AI services such as ChatGPT, Claude, Gemini, and Grok, brands that inspire instant recognition and confidence.

Although they went by different names, displayed varied logos, and carried distinct descriptions, all 30 extensions were fundamentally identical beneath the surface. They ran the same underlying code, requested the same broad permissions, and funneled data to the same concealed servers.

LayerX researchers described the approach as “extension spraying”, flooding the store with near-identical variants to evade detection and removal by Chrome Web Store moderators. The strategy paid off: several even earned “featured” placement, boosting their apparent legitimacy and helping rack up more installations.

What made these extensions particularly insidious was their method of operation. Instead of performing any genuine AI processing locally on the user’s device, they pulled in hidden full-screen overlays hosted on attacker-controlled servers, one confirmed domain being tapnetic.pro.

This setup allowed the operators to alter the extension’s behavior on the fly, without ever submitting updates through Google’s review process. Users had no way to spot the shifts.

Once active, the extensions could extract text, page titles, and other elements from any site a person visited, including protected pages that required logins, such as workplace portals or personal accounts, and relay everything to remote servers.

Gmail users in the crosshairs

Fifteen of the 30 extensions zeroed in on Gmail users specifically. LayerX dubbed this group the “Gmail integration cluster.” Marketed under separate names and pitched for different uses, all 15 shared the exact same code targeting Gmail. It injected scripts directly into Gmail’s interface, repeatedly grabbing the text of any open conversations visible on screen.

In simpler terms, full email content, including drafts and entire threads, could be pulled from Gmail and shipped off to the attackers’ servers. The report added that using Gmail’s built-in AI tools, such as smart replies or message summaries, sometimes triggered even greater capture of content, sending it beyond Google’s ecosystem.

This fits into a broader and worsening pattern. LayerX pointed out that only a month prior, they exposed 16 other extensions designed to steal session tokens from ChatGPT accounts, impacting over 900,000 users. In another case, two AI sidebar extensions leaked chat histories from DeepSeek and ChatGPT, affecting an additional 900,000 installs.

With Chrome boasting roughly 3 billion users globally and Gmail serving 2 billion, the browser’s extension ecosystem makes an especially tempting target for this kind of operation.

Anyone who is worried they’ve been hit can check LayerX’s published list of the malicious extensions. Simply head to “chrome://extensions” in your browser to inspect installed items and uninstall anything questionable. Enabling two-step verification on accounts is another smart step right now.

Zargarov delivered a blunt caution: “As generative AI continues to gain popularity, defenders should expect similar campaigns to proliferate.” Security professionals emphasize that the safest route is relying on AI features already integrated into trusted apps and platforms, rather than rolling the dice on unfamiliar third-party extensions.

The smartest crypto minds already read our newsletter. Want in? Join them.

Market Opportunity
Solchat Logo
Solchat Price(CHAT)
$0.0566
$0.0566$0.0566
-3.57%
USD
Solchat (CHAT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

UAE’s Central Bank Approves the DSSC Stablecoin Launch by IHC, FAB, and Sirius

UAE’s Central Bank Approves the DSSC Stablecoin Launch by IHC, FAB, and Sirius

The post UAE’s Central Bank Approves the DSSC Stablecoin Launch by IHC, FAB, and Sirius appeared on BitcoinEthereumNews.com. CBUAE has approved the dirham-backed
Share
BitcoinEthereumNews2026/02/13 04:30
Unyielding Challenges Stall US Crypto Bill Progress

Unyielding Challenges Stall US Crypto Bill Progress

The post Unyielding Challenges Stall US Crypto Bill Progress appeared on BitcoinEthereumNews.com. The enduring quest to establish a regulatory framework for cryptocurrencies
Share
BitcoinEthereumNews2026/02/13 04:04
Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple!

Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple!

Buterin unveils Ethereum’s strategy to tackle quantum security challenges ahead. Ethereum focuses on simplifying architecture while boosting security for users. Ethereum’s market stability grows as Buterin’s roadmap gains investor confidence. Ethereum founder Vitalik Buterin has unveiled his long-term vision for the blockchain, focusing on making Ethereum quantum-secure while maintaining its simplicity for users. Buterin presented his roadmap at the Japanese Developer Conference, and splits the future of Ethereum into three phases: short-term, mid-term, and long-term. Buterin’s most ambitious goal for Ethereum is to safeguard the blockchain against the threats posed by quantum computing.  The danger of such future developments is that the future may call into question the cryptographic security of most blockchain systems, and Ethereum will be able to remain ahead thanks to more sophisticated mathematical techniques to ensure the safety and integrity of its protocols. Buterin is committed to ensuring that Ethereum evolves in a way that not only meets today’s security challenges but also prepares for the unknowns of tomorrow. Also Read: Ethereum Giant The Ether Machine Takes Major Step Toward Going Public! However, in spite of such high ambitions, Buterin insisted that Ethereum also needed to simplify its architecture. An important aspect of this vision is to remove unnecessary complexity and make Ethereum more accessible and maintainable without losing its strong security capabilities. Security and simplicity form the core of Buterin’s strategy, as they guarantee that the users of Ethereum experience both security and smooth processes. Focus on Speed and Efficiency in the Short-Term In the short term, Buterin aims to enhance Ethereum’s transaction efficiency, a crucial step toward improving scalability and reducing transaction costs. These advantages are attributed to the fact that, within the mid-term, Ethereum is planning to enhance the speed of transactions in layer-2 networks. According to Butterin, this is part of Ethereum’s expansion, particularly because there is still more need to use blockchain technology to date. The other important aspect of Ethereum’s development is the layer-2 solutions. Buterin supports an approach in which the layer-2 networks are dependent on layer-1 to perform some essential tasks like data security, proof, and censorship resistance. This will enable the layer-2 systems of Ethereum to be concerned with verifying and sequencing transactions, which will improve the overall speed and efficiency of the network. Ethereum’s Market Stability Reflects Confidence in Long-Term Strategy Ethereum’s market performance has remained solid, with the cryptocurrency holding steady above $4,000. Currently priced at $4,492.15, Ethereum has experienced a slight 0.93% increase over the last 24 hours, while its trading volume surged by 8.72%, reaching $34.14 billion. These figures point to growing investor confidence in Ethereum’s long-term vision. The crypto community remains optimistic about Ethereum’s future, with many predicting the price could rise to $5,500 by mid-October. Buterin’s clear, forward-thinking strategy continues to build trust in Ethereum as one of the most secure and scalable blockchain platforms in the market. Also Read: Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse? The post Vitalik Buterin Reveals Ethereum’s Bold Plan to Stay Quantum-Secure and Simple! appeared first on 36Crypto.
Share
Coinstats2025/09/18 01:22