All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Millions of people now treat AI chatbots like a private notebook, typing in everything from work emails to health worries to money questions. But a browser extension that promised to make those conversations better was quietly copying all of them.
Security researchers recently found that a popular Chrome extension with about 100,000 installs was recording every prompt and reply users typed across nine major AI platforms, then sending it all to the developer's servers.[1] It's a sharp reminder that malicious Chrome extensions, even ones that look helpful and sit right in your browser, can watch nearly everything you do online.
Why malicious chrome extensions are a bigger risk than you think
How to check and remove risky chrome extensions right now
Bottom line
How a "helpful" AI extension got caught recording your chats
The extension, called Prompt Optimizer – SecondBrain, is marketed as a tool that rewrites your prompts to get sharper answers from AI. It does do that. But according to a security analysis by researcher Jean-Marie, it also copies every prompt you enter and every response the AI sends back, across ChatGPT, Claude, Gemini, Grok, Meta AI, DeepSeek, Perplexity, and Microsoft Copilot.
The collection reportedly begins the moment you install it, whether or not you ever use the prompt feature, as reported by CybersecurityNews and independently confirmed by CyberPress. There is no working off switch. The only toggle in the extension controls whether a floating button shows up on the page. Think of it like a notetaker sitting behind you, copying everything you write down, including the drafts you meant to delete.
The most troubling part is the gap between what the extension discloses and what researchers say it actually does. SecondBrain's privacy policy tells users that saved prompts are "stored locally in your browser," that prompt text is sent to the company only "when you optimize a prompt," and even warns people not to paste "secrets, passwords, API keys, private client data, or sensitive personal information."
The security analysis describes something far broader: it says the extension automatically captures every prompt and every AI reply across all nine platforms the moment it's installed, whether or not you ever use the optimizer, then encrypts and ships them to the company's servers using a key the company controls.
In other words, the capture the researcher describes goes well beyond the single opt-in step the policy spells out. The extension can even pull conversations out of business versions of Microsoft Copilot, which means company data could leak right alongside personal chats.
The extension is no longer available on the Chrome Web Store, though the SecondBrain website remains online.
Why malicious chrome extensions are a bigger risk than you think
This was not a one-off. A separate investigation found 287 Chrome extensions quietly harvesting browsing data from an estimated 37.4 million users. Browser extensions are risky in a way that's easy to miss, because many of them ask for broad permission to "read and change all your data on the websites you visit," and most of us click through that install screen without a second thought.
Here's what that means for you. Anything you paste into a chatbot, a health question, a bank statement, a work document, even a password, could be captured by an extension you trusted.
This also isn't the first trusted-looking extension to put user data at risk, and it won't be the last. A little caution goes a long way, and knowing how to spot a malicious extension is the first step.
How to check and remove risky chrome extensions right now
You don't need to be technical to clean up your browser. Here's how to remove a Chrome extension you don't trust and lock things down.
- Audit what you have installed. Type chrome://extensions into your browser bar and review the full list. Remove anything you don't recognize or no longer use.
- Check the permissions on the ones you keep. Be wary of any extension that can read and change data on every site you visit unless there's a clear reason it needs that access.
- Remove SecondBrain if you have it. Look for the extension ID aajjgdpofhhcjmjoombjdfepplndhgcp and delete it. Because there's no in-app off switch, removing the extension is what actually stops the data collection.
- Run a security scan. A risky extension can leave other junk behind, so scan your device with trusted anti-malware software or a spyware removal tool.
- Think before you paste. No extension audit replaces good habits. Keep sensitive details like passwords and account numbers out of AI chatbots when you can.
Given how easily a bad extension can slip past you, it helps to have security software built for the browser itself, where this kind of threat lives, rather than a one-time cleanup. Look for a tool that runs in the background, warns you about risky extensions and shady sites in real time, and helps you get rid of anything harmful. Guardio is designed for exactly that: it focuses on browser-based threats, flags dangerous extensions and phishing attempts as you browse, and can help you remove them before they do damage.
Bottom line
The SecondBrain case is a useful wake-up call: a browser extension can be just as invasive as any app you install, and "helpful" does not mean safe.
Take a few minutes to audit your extensions, keep security software running in the background, and be choosy about what you type into AI tools. Malicious Chrome extensions count on you not looking. Looking is most of the battle.
[1] BrainDrain: SecondBrain's Prompt Optimizer Collects Your AI Chats without ever using the extension