A browser crypto wallet can reveal much more than the user-selected address. Experts of the University of Leuven found that popular extensions allow you to link several accounts of one owner, track its transitions between sites and compare conventional Internet activity with the state of cryptocurrency assets.
The authors tested 85 wallets from the Chrome extension store, which are used by more than 35 million people in total. The analysis covered network requests, permitting operation and wallet interaction with 30 popular Ethereum applications. Experts have identified five threats to confidentiality, both with the background exchange of data and with the access of sites to the interfaces of extensions.
One of the problems arises during the usual check of the balance sheet and the history of operations. Wallets send requests with public addresses to external services, and the order and time of such appeals allow you to determine which addresses belong to one person. Similar signs were found in 17 wallets, which are used by about 23 million people, or 65.4% of the audience studied expansions.
Another surveillance channel is associated with the mechanism of detection of installed wallets. The site can learn the names and combination of extensions in the browser without permission, turning such a set into a stable digital fingerprint. The vulnerability was supported by 36 wallets with a total audience of about 29 million users. Cleaning cookies and these sites in this case does not prevent the visitor from recognizing.
Particularly dangerous are the permits that continue to operate after leaving the application. Of the 36 compatible wallets, 22 did not delete previously issued access properly and continued to return the site address upon subsequent visits. The old address allows you to link new sessions, other wallets and several accounts of one owner. The problem is exacerbated by the applications themselves: only 11 out of 30 verified services really revoked the permission when you press the exit button.
Experts also показалиshowed how an advertising or analytical code can get a wallet address on a regular website not related to cryptocurrencies. An invisible built-in unit with a previously visited application is used for the attack. The interface inside such a block revealed 23 browser extensions, covering almost 28 million users. In 14 cases, the address remained available even after the extension is blocked.
After receiving an address, the surveillance service can study the open blockchain data, including balance, operations and tokens, and then compare them with the information sites visited, purchases, search queries, email or phone number. Such a scenario is able to deprive the owner of the wallet of pseudonym without stealing keys and confirming operations.
The authors propose to prohibit wallets from combining several addresses in one network request, limit the validity of permits and require repeated consent to access accounts. Extensions should also transfer their interfaces only to the main page, and applications are advised to prohibit downloading within third-party sites. According to experts, the problem is systemic and is not related to individual errors, but with how the entire ecosystem of browser wallets works.
The authors tested 85 wallets from the Chrome extension store, which are used by more than 35 million people in total. The analysis covered network requests, permitting operation and wallet interaction with 30 popular Ethereum applications. Experts have identified five threats to confidentiality, both with the background exchange of data and with the access of sites to the interfaces of extensions.
One of the problems arises during the usual check of the balance sheet and the history of operations. Wallets send requests with public addresses to external services, and the order and time of such appeals allow you to determine which addresses belong to one person. Similar signs were found in 17 wallets, which are used by about 23 million people, or 65.4% of the audience studied expansions.
Another surveillance channel is associated with the mechanism of detection of installed wallets. The site can learn the names and combination of extensions in the browser without permission, turning such a set into a stable digital fingerprint. The vulnerability was supported by 36 wallets with a total audience of about 29 million users. Cleaning cookies and these sites in this case does not prevent the visitor from recognizing.
Particularly dangerous are the permits that continue to operate after leaving the application. Of the 36 compatible wallets, 22 did not delete previously issued access properly and continued to return the site address upon subsequent visits. The old address allows you to link new sessions, other wallets and several accounts of one owner. The problem is exacerbated by the applications themselves: only 11 out of 30 verified services really revoked the permission when you press the exit button.
Experts also показалиshowed how an advertising or analytical code can get a wallet address on a regular website not related to cryptocurrencies. An invisible built-in unit with a previously visited application is used for the attack. The interface inside such a block revealed 23 browser extensions, covering almost 28 million users. In 14 cases, the address remained available even after the extension is blocked.
After receiving an address, the surveillance service can study the open blockchain data, including balance, operations and tokens, and then compare them with the information sites visited, purchases, search queries, email or phone number. Such a scenario is able to deprive the owner of the wallet of pseudonym without stealing keys and confirming operations.
The authors propose to prohibit wallets from combining several addresses in one network request, limit the validity of permits and require repeated consent to access accounts. Extensions should also transfer their interfaces only to the main page, and applications are advised to prohibit downloading within third-party sites. According to experts, the problem is systemic and is not related to individual errors, but with how the entire ecosystem of browser wallets works.