Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeOKX Wallet
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01On x.com / twitter.com a dedicated content script (x.js, 1.6 MB) MutationObserver-scrapes every tweet's text and link nodes, extracts coin/contract identifiers, injects buy widgets, and reports interaction events with the deviceId to OKX's analytics endpoint.
  2. 02On every HTTPS site, content script (instantTrade.js) runs a MutationObserver and can inject a draggable OKX trading iframe; user click events report the navigated URL to OKX analytics endpoint with deviceId.
  3. 03Content script injects EIP-1193 / multi-chain wallet provider (window.okxwallet, window.ethereum) into every http(s) page via web_accessible_resources/inpage.js bridge.
+2 more findings locked
OTHER EXTENSIONS

Is OKX Wallet safe?

Medium risk

No summary available.

OKX MALTA LTDv3.102.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.okex.walletExtension.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact