Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wallet addresses and potentially tie pseudonymous crypto identities to real names. Despite wallet makers acknowledging the issue, only a few have implemented fixes, highlighting a lack of industry-wide standards and a reluctance to fully address the problem. The vulnerabilities stem from how wallets interact with websites and blockchain servers, and the design of the wallets themselves.
Researchers at KU Leuven have identified critical privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. The study, published on arXiv and set for presentation at PETS 2026, reveals that these wallets leak enough address information to link separate wallet addresses and potentially tie pseudonymous crypto identities to real names. The core issue lies in how the wallets communicate with websites and blockchain servers, exposing address information in the clear to anyone running a script on those sites.
Specifically, the researchers found that many wallets leak address information to outside servers, allowing trackers to stitch together a user’s separate addresses into a single profile. Furthermore, the wallets’ design allows them to hand out addresses from inside embedded frames, enabling trackers to link a crypto wallet to an unrelated website and reveal a user’s identity. Despite the severity of these vulnerabilities, only a few wallet makers, including Coinbase Wallet and Coin98, have implemented fixes by February 2026.
MetaMask dismissed the issue as a known issue and closed the report as a duplicate, stating it had no immediate plans to stop injecting its provider. Other wallet makers, such as OKX, Bybit, Backpack, and Core, categorized the findings as low-risk or out of scope. The study builds on previous research highlighting address leaks to servers, but distinguishes itself by mapping out the cross-site tracking and demonstrating how the same leak can be used to unmask people. Unlike fake wallet extensions that steal keys, this vulnerability is built into the wallet design itself, and doesn't involve stealing funds.
For users, the only partial solution is to clear out old site permissions. However, the bigger fixes require wallet makers to stop exposing themselves inside embedded frames and to establish an industry standard defining what ‘logging out’ truly means. The research underscores a gap in the industry’s response to privacy concerns and the need for proactive measures beyond simply warning users about potential risks.
