Browser Crypto Wallets May Expose Addresses and Link User Activity Across Sites

Colleagues, I’d like to flag a cybersecurity study: testing 85 crypto wallet extensions revealed risks of address leakage and cross-site tracking.
Key findings:
• wallets may transmit addresses to external servers in plaintext;
• some extensions can link multiple addresses belonging to the same user;
• after Disconnect, access often persists unless the site is removed manually;
• through an iframe, an address can leak on another site and de-anonymize a profile.
Importantly, this is not a hack, but an architectural and logic issue.
Why it matters: Web3 privacy depends not only on keys, but also on how a wallet interacts with websites.
How do you assess these risks — a bug or a design feature?
#cybersecurity #Web3 #privacy #crypto

