Browser extensions can help hackers steal your cryptocurrencies, warns Casa CEO Jeremy Welch.
"Browser extensions pose significant risks, and those risks have not been discussed until now," Welch said.

Extensions can collect a wealth of data, which can be leaked, stolen, and used by scammers. One example is browser history, which can expose users' online habits, including crypto-related visits.
“Make sure you don’t expose your bitcoin addresses anywhere,” Welch warned.
Another thing to keep in mind is that some extensions record KYC and can be leaked to fraudsters. The only major multisig system that currently requires KYC is the one provided by Unchained Capital, Welch said. He warns about shared software that collects identity data.

For example, Welch showed how a browser extension that provides wallpapers with inspirational quotes or other content actually steals data if you fill out KYC forms. The malware steals graphical data, such as a photo from your driver's license, which is recorded as a code and then easily decoded, providing a hacker with an actual image of your ID document.
Audio data theft
They happen in the background, without the user noticing.
The same wallpaper extension can change a receiving address when you try to send cryptocurrency to someone (or yourself), sending it instead to the hacker's wallet. The popularity of browser extensions makes the situation quite dangerous, Welch notes.

Even if a user is very careful and selective about what they use, software can be upgraded and gain new, unsafe features without them noticing.
Welch pointed out that many well-known apps collect personal data, including password managers, text editing app Grammarly, Joule extension for in-browser Lighting transactions, and Lolli bitcoin-earning extension.
The solution? It's not easy. Developers can only create better tools that will make the user experience safer and better.
