📈 Get daily crypto insights that make you smarter about your money

Malicious Chrome Extension Drains $1 Million From Binance Trader in Sophisticated Cookie Hijacking Attack

The Artist’s Journey

The cryptocurrency security landscape faces a new breed of threat in June 2024, as a Chinese Binance trader discovered that $1 million had been siphoned from their account through a remarkably sophisticated browser-based attack. The incident, which occurred on May 24 but came to light in early June, exposes a vulnerability that bypasses both passwords and two-factor authentication—two security layers most users consider impenetrable.

The attack vector was a seemingly innocuous Google Chrome extension called Aggr, marketed as a trading tool aggregator promoted by influencers and Telegram channels. In reality, the extension functioned as a session cookie thief, quietly harvesting browser cookies that maintain login sessions and transmitting them to the attacker’s servers. With those cookies in hand, the hacker bypassed every traditional security measure Binance had in place.

Collection Mechanics

The mechanics of the attack reveal an alarming level of sophistication. The Aggr extension, which presented itself as an open-source trading aggregation tool, was designed to harvest session cookies from browser storage. When a user logs into Binance, the exchange stores authentication cookies that keep the session active. The extension extracted these cookies and sent them to the attacker, who used them to impersonate the logged-in user.

Because the attacker possessed valid session cookies, Binance’s security systems treated the unauthorized access as a normal login from the legitimate user. The hacker executed a series of rapid-fire transactions—converting various cryptocurrencies and withdrawing funds through multiple wallets—before the victim even realized what had happened. The trader reported receiving no security notifications from Binance during the attack, raising serious questions about the exchange’s real-time monitoring capabilities.

The stolen funds moved through a complex laundering pipeline involving cross-chain bridges and mixing services, making recovery virtually impossible. Blockchain analysts traced portions of the funds through Tornado Cash and various decentralized exchanges before the trail went cold.

Utility and Perks

The Aggr extension had been distributed through channels that lent it credibility. Multiple cryptocurrency influencers and trading-focused Telegram groups with thousands of subscribers promoted the tool as a legitimate trading aggregator. The extension was listed as open-source on GitHub, allowing technically minded users to inspect the code—but the malicious payload was obfuscated within dependencies that most users would never review.

This attack pattern represents an evolution in crypto-targeted social engineering. Rather than phishing for credentials directly, attackers are increasingly embedding malware within tools that traders genuinely want to use. The approach exploits the trust that the crypto community places in open-source software and peer recommendations.

Bitcoin trades at approximately $69,305 as of June 8, 2024, and the broader crypto market capitalization hovers near $2.57 trillion, according to CoinMarketCap data. At these valuations, even a single successful attack yielding $1 million represents a fraction of daily trading volume—making individual incidents harder to detect amid the noise of legitimate transactions.

Secondary Market Action

The incident has triggered a wave of concern across trading communities. Multiple security researchers have since identified similar Chrome extensions targeting users of other major exchanges including OKX, Bybit, and Kraken. The common thread: all exploit the same fundamental weakness in cookie-based session management that browsers have relied on for decades.

Binance’s response has drawn criticism. The victim reported that customer support was slow to react, and the exchange has not publicly acknowledged the specific attack vector. Security experts note that exchanges could mitigate such attacks by implementing additional verification steps for sensitive actions like withdrawals—such as requiring biometric confirmation or a separate hardware key for large transfers—regardless of whether a valid session cookie exists.

The cybersecurity firm that investigated the incident confirmed that the Aggr extension had been downloaded by thousands of users before being flagged. Other malicious extensions with similar functionality remain available in the Chrome Web Store, exploiting the lag between malware identification and platform enforcement.

Final Verdict

This $1 million heist serves as a stark reminder that the weakest link in cryptocurrency security is often the user’s browser environment, not the blockchain itself. For traders and investors, the implications are clear: browser extensions should be treated with the same skepticism as unsolicited email attachments. Hardware wallets remain the gold standard for storing significant crypto holdings, and users should regularly audit their browser extensions, revoke unnecessary permissions, and enable withdrawal whitelist features on exchange accounts. The era of trust-by-default in crypto tools is over. Every piece of software that interacts with your browser sessions is a potential attack surface, and the sophistication of these attacks will only increase as cryptocurrency valuations continue to rise.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making investment or security decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Malicious Chrome Extension Drains $1 Million From Binance Trader in Sophisticated Cookie Hijacking Attack”

  1. session cookie theft bypassing 2fa is terrifying because theres literally nothing the user can do differently. your 2fa works fine, they just dont need it

    1. Diego Morales

      pwned_again session cookie theft on aggr extension bypassing 2fa leaves users with zero defense

    2. pwned_again is right, 2fa literally cannot help when the attacker has your session cookie. the server thinks its you because the cookie IS you

      1. this is why hardware wallets exist. if your funds are accessible through a browser, they are not your funds

        1. ext_bouncer hardware wallet eliminates this attack vector but 99% of traders keep funds on exchange for liquidity. cold storage advice falls flat when people are actively trading

      2. Tomas F. session cookies ARE you is the scariest part of this. 2FA, strong password, hardware key, none of it matters when the attacker has your session token

  2. Aggr extension stealing session cookies and bypassing 2FA completely. if your funds are accessible through a browser session they are not your funds. hardware wallet or nothing

    1. cookie_jar_ Binance not flagging logins from new IPs via session cookies is the real failure. IP geolocation on cookie-based sessions is trivial to implement

  3. open source repo with a different compiled build than what was distributed is the oldest supply chain trick. electrum had the same thing in 2018

  4. session anomaly detection on Binance flagged nothing while someone logged in from a completely new IP with stolen cookies. my bank catches that but a crypto exchange doesnt

  5. The Aggr extension was promoted by influencers on Telegram. When will people stop trusting random browser extensions recommended by anon accounts?

    1. olga they trust them because the extensions look legit and the influencers have 100k followers. social engineering at scale

    2. influencers promoted a wallet drainer for a cut of the affiliate revenue. names should be named and accounts reported

      1. the real issue is Binance having no session anomaly detection. logging in from a new device with just cookies should trigger at minimum an email confirmation

        1. Kira V. no session anomaly detection on a tier 1 exchange is wild. my bank flags me for logging in from a new city but binance just lets the cookie through

        2. sess_hijack_rat_

          Binance not having session anomaly detection on cookie logins is still wild to me in 2026. my local bank flags a login from a new device but a tier 1 crypto exchange just lets it through

  6. the Aggr extension had 50k+ installs before anyone noticed. chrome web store review process is basically non-existent for anything that isnt obvious malware

    1. 50k+ installs on the Aggr extension before anyone noticed. google needs to be liable for what their store distributes at this point

  7. vault_macaque_

    the Aggr extension being open source is what made it so effective as a trojan. anyone could audit the public repo while the actual distributed build had the cookie skimmer compiled in

  8. Aggr being open source with a different compiled build is the oldest trick. read the source, ignore the binary. but nobody actually builds from source so here we are

    1. cookie_ghost_

      Hyun-woo P. the open source vs compiled build mismatch is such an old attack vector. happened with electrum wallets in 2018 too. nobody learns

  9. 50k installs on the Aggr extension and Google only removed it after someone lost a million. the Chrome Web Store review process is basically non-existent for anything that isnt obvious malware

  10. tracie_m the influencer promotion angle is what made this work. 100k followers trust the recommendation and nobody actually reads the permissions popup before clicking accept

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,868.00+1.0%ETH$2,578.15+5.2%SOL$102.39+2.7%BNB$730.23+3.1%XRP$1.37+1.5%ADA$0.2095+0.4%DOGE$0.0857+2.6%DOT$1.07-1.9%AVAX$7.60-0.1%LINK$11.78+1.4%UNI$6.17+3.1%ATOM$1.67-6.1%LTC$54.01+3.3%ARB$0.1453-1.9%NEAR$2.61+4.8%FIL$0.8055+0.8%SUI$0.7419+0.0%BTC$77,868.00+1.0%ETH$2,578.15+5.2%SOL$102.39+2.7%BNB$730.23+3.1%XRP$1.37+1.5%ADA$0.2095+0.4%DOGE$0.0857+2.6%DOT$1.07-1.9%AVAX$7.60-0.1%LINK$11.78+1.4%UNI$6.17+3.1%ATOM$1.67-6.1%LTC$54.01+3.3%ARB$0.1453-1.9%NEAR$2.61+4.8%FIL$0.8055+0.8%SUI$0.7419+0.0%
Scroll to Top