Disrupting ShieldGuard: a security extension primed to drain crypto wallets
ID: e0d1463a-3f23-5d96-9a3f-a88a88ed4287
STIX ID: report--e0d1463a-3f23-5d96-9a3f-a88a88ed4287
Feed Name: Okta Threat Intelligence
Date Published: 2026-03-16
Date Updated: 2026-08-05
Author: , Yang Wang, Simon Conant, Adam Smallhorn
Okta Threat Intelligence uncovered and helped dismantle "ShieldGuard", a fraudulent cryptocurrency project that distributed a malicious browser extension via a multi-level marketing airdrop campaign; the extension masqueraded as a wallet-protection tool but harvested wallet addresses and sensitive data from major crypto platforms (Binance, Coinbase, MetaMask, OpenSea, Phantom, Uniswap) and Google services, and captured full HTML content after user sign-ins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
