← All stories
● Covered by 1 source · 1 reportHigh impact

Research Reveals Privacy Flaws in 85 Crypto Wallet Extensions

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Study tested 85 popular crypto wallet extensions.
  • Identified address linking and cross-site tracking vulnerabilities.
  • 36 wallets can be fingerprinted, accounting for 82% of users.

Overview of Findings

Researchers from KU Leuven conducted an extensive evaluation of 85 popular cryptocurrency wallet extensions available on the Chrome Web Store. These wallets collectively cater to approximately 35 million users and exhibit vulnerabilities that compromise user privacy.

Address Linking Vulnerabilities

The study highlighted a significant flaw whereby multiple wallet addresses owned by the same user can be linked together. This is achieved through requests made to external servers, which reveal a user's address in clear text. Seventeen wallets were identified to have exposed connections between user addresses, potentially allowing server operators to create a comprehensive profile of an individual based on their wallet activity.

Limitations of Wallet Logout Mechanisms

Another concerning issue found was that logging out from wallet extensions does not necessarily disconnect them from websites. This initialization allows websites to detect which wallets are installed on a user’s browser, functioning as a fingerprinting mechanism. Among the wallets studied, 36 demonstrated this capability, affecting about 82% of the user base evaluated.

Industry Response

Upon pre-publication disclosure of these vulnerabilities to wallet developers, many did not classify the issues reported as bugs. This response raises questions about the security priorities among developers in the crypto wallet space and the importance of addressing privacy concerns.

Implications for Users and Developers

The findings underscore the need for improved privacy practices in cryptocurrency wallets. Users may unknowingly expose their anonymity, while developers are urged to reassess the security frameworks underlying these wallet extensions to prevent potential data misuse.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A study by KU Leuven on 85 popular crypto wallet extensions identified significant privacy vulnerabilities, including user address leaks and tracking risks. These weaknesses could potentially enable tracking of users across different websites, undermining the anonymity intended by these wallets.