Skip to content
Brief Security & Trust ·

Researchers show attack on SConnect login tool used for SWIFT

Bay Area Labs says a flaw in a hardware-key extension let a web page run code in its own tests.

In brief
  • Bay Area Labs found a critical flaw in SConnect, a Thales browser extension used for SWIFT and government logins. Thales patched two versions, removed a third and published CVE-2026-18397.
  • The 18% success rate and speed come from the researchers' own tests. Worse attacks are unproven, and how many users still run SConnect is unknown.

Dark Reading reported on Oct. 2 that Bay Area Labs found a critical flaw in SConnect, a Thales browser extension for hardware-key logins. Dark Reading says the Chrome version has over 1 million users and the tool serves SWIFT and government sites. The researchers say the extension accepts messages from any web page. An oversized, invalid signature makes its check fail silently, yet it reads leftover memory. Attacker-sprayed bytes there can pass as valid, and a malicious DLL (a code file) loads. Bay Area Labs concluded Thales wrote that check itself. Thales patched the Apple and Chrome versions in August, removed the Edge version in September, and published CVE-2026-18397 on Oct. 1, rated 9.4 of 10 on CVSS 4.0.

In the researchers' own tests, an AI-agent-driven attack worked about 18% of the time and took six to 10 seconds. Failed tries showed no visible error. SConnect is now end of life. Thales had not replied to Dark Reading. Worse attacks, such as stolen sessions or money transfers, are unproven because the team had no SWIFT 3SKey. How many users still run SConnect is unknown.

Researcher James Arnott says this once needed nation-state effort, but agents built his exploit. That is his view. Teams that use hardware keys should check which middleware they still run, and whether it is end of life.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Dark Reading.