Your ChatGPT chats could be secretly stolen via Chrome - experts

The Chrome extension Prompt Optimizer – SecondBrain, installed by ~100,000 users, secretly intercepted requests and responses in nine AI services, including ChatGPT, Gemini, Claude, Grok, DeepSeek, Perplexity, Copilot, Meta AI, and Microsoft 365 Copilot. Data was transmitted to remote servers via network traffic interception. Disabling collection is impossible; encryption keys are held by developers. Experts recommend removing the extension and checking connections to secondbrain.is domains.

Cybersecurity experts have discovered that the Google Chrome browser extension Prompt Optimizer – SecondBrain, marketed as a tool for improving AI chat interactions, was actually engaged in covert data collection. Installed by approximately 100,000 users, the extension automatically intercepted requests and responses in nine popular AI services: ChatGPT, Gemini, Claude, Grok, DeepSeek, Perplexity, Copilot, Meta AI, and Microsoft 365 Copilot. Code analysis revealed the use of network traffic interception mechanisms (window.fetch, XMLHttpRequest, WebSocket) to transmit conversations to remote servers in real time. Particularly dangerous is access to corporate correspondence in Microsoft 365 Copilot. Disabling data collection through the extension's settings is impossible—transmission parameters activate automatically upon launch, and privacy settings are disabled. Although data is encrypted, the keys are held by developers, potentially allowing them to read intercepted chats. Experts recommend immediately removing the extension, checking the system for connections to secondbrain.is domains, and for organizations to restrict installation of such add-ons through corporate policies.

Your ChatGPT chats could be secretly stolen via Chrome - experts