A 'Helpful' AI Extension Just Got Caught Recording All Your Chats

A popular AI helper extension was caught secretly recording everything users typed into ChatGPT, Claude, and Gemini, a reminder that browser extensions can quietly spy on you.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Millions of people now treat AI chatbots like a private notebook, typing in everything from work emails to health worries to money questions. But a browser extension that promised to make those conversations better was quietly copying all of them.

Security researchers recently found that a popular Chrome extension with about 100,000 installs was recording every prompt and reply users typed across nine major AI platforms, then sending it all to the developer's servers.[1] It's a sharp reminder that malicious Chrome extensions, even ones that look helpful and sit right in your browser, can watch nearly everything you do online.

In this article
How a "helpful" AI extension got caught recording your chats
Why malicious chrome extensions are a bigger risk than you think
How to check and remove risky chrome extensions right now
Bottom line

How a "helpful" AI extension got caught recording your chats

The extension, called Prompt Optimizer – SecondBrain, is marketed as a tool that rewrites your prompts to get sharper answers from AI. It does do that. But according to a security analysis by researcher Jean-Marie, it also copies every prompt you enter and every response the AI sends back, across ChatGPT, Claude, Gemini, Grok, Meta AI, DeepSeek, Perplexity, and Microsoft Copilot.

The collection reportedly begins the moment you install it, whether or not you ever use the prompt feature, as reported by CybersecurityNews and independently confirmed by CyberPress. There is no working off switch. The only toggle in the extension controls whether a floating button shows up on the page. Think of it like a notetaker sitting behind you, copying everything you write down, including the drafts you meant to delete.

The most troubling part is the gap between what the extension discloses and what researchers say it actually does. SecondBrain's privacy policy tells users that saved prompts are "stored locally in your browser," that prompt text is sent to the company only "when you optimize a prompt," and even warns people not to paste "secrets, passwords, API keys, private client data, or sensitive personal information."

The security analysis describes something far broader: it says the extension automatically captures every prompt and every AI reply across all nine platforms the moment it's installed, whether or not you ever use the optimizer, then encrypts and ships them to the company's servers using a key the company controls.

In other words, the capture the researcher describes goes well beyond the single opt-in step the policy spells out. The extension can even pull conversations out of business versions of Microsoft Copilot, which means company data could leak right alongside personal chats.

The extension is no longer available on the Chrome Web Store, though the SecondBrain website remains online.

Why malicious chrome extensions are a bigger risk than you think

This was not a one-off. A separate investigation found 287 Chrome extensions quietly harvesting browsing data from an estimated 37.4 million users. Browser extensions are risky in a way that's easy to miss, because many of them ask for broad permission to "read and change all your data on the websites you visit," and most of us click through that install screen without a second thought.

Here's what that means for you. Anything you paste into a chatbot, a health question, a bank statement, a work document, even a password, could be captured by an extension you trusted.

This also isn't the first trusted-looking extension to put user data at risk, and it won't be the last. A little caution goes a long way, and knowing how to spot a malicious extension is the first step.

Not sure whether an extension is trustworthy? Check the permissions it asks for, the developer's track record, and recent reviews before you install it. Learn how to recognize a malicious extension.

How to check and remove risky chrome extensions right now

You don't need to be technical to clean up your browser. Here's how to remove a Chrome extension you don't trust and lock things down.

  1. Audit what you have installed. Type chrome://extensions into your browser bar and review the full list. Remove anything you don't recognize or no longer use.
  2. Check the permissions on the ones you keep. Be wary of any extension that can read and change data on every site you visit unless there's a clear reason it needs that access.
  3. Remove SecondBrain if you have it. Look for the extension ID aajjgdpofhhcjmjoombjdfepplndhgcp and delete it. Because there's no in-app off switch, removing the extension is what actually stops the data collection.
  4. Run a security scan. A risky extension can leave other junk behind, so scan your device with trusted anti-malware software or a spyware removal tool.
  5. Think before you paste. No extension audit replaces good habits. Keep sensitive details like passwords and account numbers out of AI chatbots when you can.

Given how easily a bad extension can slip past you, it helps to have security software built for the browser itself, where this kind of threat lives, rather than a one-time cleanup. Look for a tool that runs in the background, warns you about risky extensions and shady sites in real time, and helps you get rid of anything harmful. Guardio is designed for exactly that: it focuses on browser-based threats, flags dangerous extensions and phishing attempts as you browse, and can help you remove them before they do damage.

Robust Phishing Protection Backed by $1 Million in ID Theft Insurance
Get Deal
On Guardio's website
Antivirus Software
Guardio
  • Browser security tool that monitors your email for phishing attempts and alerts you to data breaches tied to your address
  • Monitors dark web exposure for up to 5 people, with individual, couples, and family plans available
  • Includes up to $1M in identity theft insurance and a dedicated hotline if your identity is compromised

Bottom line

The SecondBrain case is a useful wake-up call: a browser extension can be just as invasive as any app you install, and "helpful" does not mean safe.

Take a few minutes to audit your extensions, keep security software running in the background, and be choosy about what you type into AI tools. Malicious Chrome extensions count on you not looking. Looking is most of the battle.

Robust Phishing Protection Backed by $1 Million in ID Theft Insurance
Get Deal
On Guardio's website
Antivirus Software
Guardio
  • Browser security tool that monitors your email for phishing attempts and alerts you to data breaches tied to your address
  • Monitors dark web exposure for up to 5 people, with individual, couples, and family plans available
  • Includes up to $1M in identity theft insurance and a dedicated hotline if your identity is compromised
Author Details
Kate Quinlan is a Senior Editor at All About Cookies, where she has tested dozens of digital security tools and contributed to more than 370 articles spanning web hosting, VPNs, ad blockers, parental controls, and data security. Before joining AAC, she managed a team of more than 150 writers at SuperSummary, where she developed editorial standards at scale. She holds a B.A. in Professional Writing from Kutztown University.

Citations

[1] BrainDrain: SecondBrain's Prompt Optimizer Collects Your AI Chats without ever using the extension