Is Inspect - Crypto | NFTs | DeFi | Web3 safe?

Medium risk

Inspect - Crypto | NFTs | DeFi | Web3 is medium risk. Interacting with the extension's overlay or popups on Twitter/X sends your logged-in handle as the analytics user ID to Segment at api.segment.io, with browser context like the user agent, linking your identity to telemetry.

nftinspectv0.0.127Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Twitter/X handle sent to Segment on overlay interactions

Interacting with the extension's overlay or popups on Twitter/X sends your logged-in handle as the analytics user ID to Segment at api.segment.io, with browser context like the user agent, linking your identity to telemetry.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The user interacts with the extension overlay or popup on Twitter/X.

The extension did this

The extension sends the logged-in Twitter/X handle as the Segment analytics user ID, along with browser context including the user agent.

02EvidenceNETWORK CAPTURE
Captured request
POSTapi.segment.io/v1/track
03EvidenceFIELD TABLE
Fields in the request
FieldValueWhy it matters
Your Twitter/X page content
@example_user (illustrative)The extension derives the logged-in account handle from the Twitter/X page and uses it as the analytics user ID.
Your browser and tab context
Mozilla/5.0 Chrome/126.0 (illustrative)The analytics event includes browser context such as navigator.userAgent, which adds device and browser detail to the interaction record.
04EvidencePLAIN NOTE
Observation

Dynamic analysis confirmed the content script sends the Twitter/X handle and navigator.userAgent to Segment during popup interactions.

Updated 17 September 2026kamfleanhcmjelnhaeljonilnmjpkcjc