X user @CryptoNakamao posted that his browser cookies were hijacked due to the malicious Chrome plug-in Aggr. The hacker manipulated his Binance account in this way, purchased the corresponding tokens in the USDT trading pair with abundant liquidity, and placed limit sell orders that exceeded the market price in the BTC, USDC and other trading pairs with scarce liquidity.
Finally, the hacker used the user's account to open leveraged transactions, bought in excess of large amounts, and completed the counter-trading, which ultimately caused a loss of 1 million US dollars.
Earlier in late May, the founder of SlowMist, Yu Xian, posted on the X platform that users need to pay attention to the browser extension AggrTrade. The application will steal the user's exchange cookies and other permission information, which has caused great user losses. Installed users should delete it as soon as possible, and modify the account passwords and 2FA of each platform, reset the transaction API, etc. Be cautious when installing and using extensions.