According to a study published by the University of Leuven, Belgium, the expansion of 85 encrypted wallet browsers has structural privacy problems and may link the user identity to the address of the chain of assets. This will make it easier for external websites to identify users and, on that basis, initiate targeted fishing or extortion.

The authority may be retained after posting

The study notes that many wallets do not simultaneously revoke address access rights after the user logs out or removes session data. As a result, it is still possible that the website will continue to identify user wallet-related information and form an ongoing follow-up.

This means that the risk does not occur only at the moment when the wallet is connected. Even if the user ends the session, the status of permission left by the partial extension may expose the address trail and increase privacy disclosure.

Partial wallet repaired problem

According to the post-disclosure processing, the Coinbase Wallet, Coin98 and Hana Wallet have installed patches to prevent unauthorized websites from tracking user information.

However, not all manufacturers have given this matter high priority. OKX Wallet, Bybit Wallet and Core Wallet classify this disclosure as low risk and therefore address priorities relatively backwards.

The study will be publicly presented in late July.

The University of Leuven plans to officially present this gap study at the PETS workshop, which will be held from 20 to 25 July 2026. At that time, the relevant technical details and the scope of the impact will be further disclosed.

Once again, the study shows that the security of encrypted ecology is not limited to conventional attacks or the theft of accounts, and that wallet expansion itself may become an entry point for the exposure of user information. For ordinary users, wallet privileges management and extended security remain high-frequency risk points.