A SimpleSwap bonus script that asks you to use Tampermonkey or paste code into your browser is a scam lure. Stop pending transfers and remove the untrusted script before using the exchange again. A genuine website address does not protect you from code that you allowed to change the page inside your own browser.
Tampermonkey is a legitimate userscript manager. The danger here is the stranger’s script installed inside it. SimpleSwap says the advertised hidden bonus is unrelated to its service and that its real loyalty benefits do not require a script or browser extension. [2]
What the fake bonus changes
Cisco Talos documented lures promising a 25% SimpleSwap bonus and, in an earlier SwapZone version, roughly 38% higher payouts. The code retrieved a payload through Google Sheets, changed deposit addresses and clipboard values, and added counterfeit bonus elements. The Tampermonkey version could run again whenever the targeted site loaded. [1]
The useful distinction is where the unwanted code runs. This browser-based scheme differs from a fake CAPTCHA that makes you run a Windows command. If you also opened PowerShell, Windows Run, an installer, or another downloaded program, follow the ClickFix command-execution response as well.
Watch for a panel promising a “25% Loyalty Bonus” or saying “Loyalty Bonus requires Bitcoin.” Those are examples of the fraudulent interface language described in the research, not instructions to follow.
Choose the response that matches what you did
- You only read the post or document. Close it. Do not install the suggested extension, run its code, or contact the promoter to test the offer. Reading a pitch alone does not establish that the userscript was installed.
- You copied code but did not execute it. Overwrite the clipboard with harmless text and close the lure. Check whether you actually pressed Enter in an execution context or saved a script in an extension; those actions change the response.
- You ran browser code or added a userscript. Stop using that browser for swaps. Close affected tabs and work through the removal steps below. Do not make a small transfer to see whether the bonus works.
- You already sent funds, signed a request, or entered a wallet secret. Use another trusted device for account and wallet response. Preserve the transaction details, then follow the separate recovery actions later in this guide.
Remove the malicious userscript
- Close every exchange and wallet tab in the affected browser. Do not refresh a pending payment page or restore the previous session. If you cannot tell what else ran, disconnect that device while you inspect it.
- Disable the extension that runs the script. In Chrome, open the menu, choose Extensions → Manage extensions, and turn off Tampermonkey or the other userscript manager involved. Unpinning its icon only hides the shortcut; it does not disable the extension. [3]
- If you installed the manager only for this offer, remove it. Use Remove on its extension card and confirm. Do not reinstall it from the promoter’s instructions or import the old script collection.
- If you need to keep a userscript manager, remove the unwanted script from its dashboard. Disconnect from the internet and keep all ordinary website tabs closed. If necessary, enable the manager only to open its own Dashboard, then disable and delete the script you added for the bonus. Review other unfamiliar entries added at the same time. Turn the manager off again until the review is finished. A friendly name or a description mentioning a loyalty API is not a safety check.
- Check the browser profile you actually used. Extensions in a work profile and a personal profile can differ. Review other browsers or devices where you deliberately installed or imported the same script. If you use script-manager backup or synchronization, remove the unwanted entry there too before restoring that collection.
- Start a fresh browsing session. After removing the unwanted code, fully exit the browser. Clear the affected site’s stored data if it still shows stale interface elements, understanding that this signs you out. Reopen the service from a trusted bookmark or its manually entered official address, with the suspect extension still disabled.
Closing a tab is only containment when a persistent script remains installed. Likewise, clearing cookies or cache is not a substitute for inspecting the extension and its saved scripts.
Check the result without sending cryptocurrency
Use a separate trusted device or browser profile with no imported extensions to verify the service and any pending order. Confirm the same order, asset and network through the provider’s official support when a deposit destination is in doubt; different orders can legitimately use different deposit addresses. Do not compare two unrelated quotes and call the difference malware.
Stop if an unexpected bonus panel remains, the suspect script reappears, or a payment address changes between the trusted source and the final confirmation screen. Do not retry the transfer. Review which browser profile is open, whether another userscript manager is active, and whether a saved collection or extension installation was restored.
A clean-looking page is not enough to resume a questionable payment. Our crypto wallet verification checklist explains how to check the recipient, full address and network independently. A hardware wallet can help you inspect a destination, but it cannot know whether an address supplied by a compromised browser belongs to the intended recipient.
When a Windows malware scan belongs in the cleanup
If you also ran a downloaded file, approved an installer, or see unwanted browser activity after removing the script, check for a wider compromise. An unwanted extension, bundled application or startup component may remain after the visible problem disappears.
On Windows, run a full Gridinsoft Anti-Malware scan, review and remove confirmed detections, then reboot and recheck if symptoms return. This helps inspect unwanted files and browser changes; it does not replace the manual userscript review, certify a payment destination, or recover cryptocurrency.
If redirects, notifications, extensions, homepage changes, or managed policies return after browser cleanup, the source is often outside the browser: an installed app, policy, scheduled task, or startup entry.
Scan this Windows PCIf the extension cannot be removed on a work-managed browser, ask your administrator to inspect the policy and script source. Do not disable company security controls to force a change.
If you already sent funds or exposed a wallet
Keep browser cleanup separate from the transaction response. Removing the script cannot undo a completed transfer.
- A transfer went to the wrong address: save the transaction hash, destination, network, amount, order identifier and lure screenshots. Contact the swap provider and any identifiable receiving service through their official channels from a trusted device. Describe the address mismatch and ask what investigation or intervention is possible; do not assume a reversal is available.
- You approved an unfamiliar contract or wallet request: review what it authorized using the wallet provider’s official guidance. Revoke unwanted spending permissions where applicable. A Bitcoin transfer and a token allowance are different events; do not follow an allowance-revocation workflow merely because the scam mentioned crypto.
- You entered a recovery phrase or private key: treat that secret as exposed. Use a trusted device to create a new wallet with a new recovery phrase and arrange protection of remaining assets. Changing an exchange password does not replace an exposed wallet key.
- You entered an exchange password on a suspicious page: change it from a trusted device, end unfamiliar sessions, and review recovery settings and account activity.
Ignore anyone who requests another payment or your recovery phrase to retrieve the funds. The online-scam response guide covers evidence preservation and reporting.
FAQ
Does installing Tampermonkey from an official store make a script safe?
No. The extension and the code you add to it are separate trust decisions. A legitimate manager can run an untrusted script. Judge the source and purpose of that script, especially when it promises extra money for changing an exchange page.
Should I block all Google Docs or delete every userscript?
Start with the entry you installed for the offer and any other untrusted additions. Broadly blocking a document service does not remove an installed script. Keep the manager disabled if you cannot confidently identify which entries belong there.
References
- Gallagher, Sean. “ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2.” Cisco Talos, September 8, 2026. Campaign research.
- SimpleSwap. “The Fake ‘SimpleSwap Bonus’ Script Making the Rounds.” September 1, 2026; accessed September 12, 2026. Official warning.
- Google. “Install and manage extensions.” Chrome Web Store Help, accessed September 12, 2026. Extension controls.

