🚨 CRITICAL PHISHING ALERT TARGETING
$TRX USERS
SlowMist reports that a counterfeit TronLink Chrome extension loads a remote phishing page via an iframe, capturing seed phrases and private keys in real time. The malware includes anti‑analysis mechanisms to evade detection, raising concerns for retail investors.
SlowMist issued an urgent warning about a malicious Chrome extension masquerading as TronLink. The extension uses Unicode bidirectional control and Cyrillic look‑alike characters to mimic the official branding, then loads a remote iframe to harvest mnemonics, private keys and passwords, exfiltrating them via Telegram Bot. It also employs anti‑analysis features such as right‑click blocking and region‑based redirects. Users are advised to uninstall the suspect extension, monitor for abnormal traffic, and transfer assets to a new wallet if any credentials were entered.
Not financial advice. Manage your risk.
#CryptoSecurity #TRX #Phishing #DeFi #WalletSafety 🔒