It Blocked Ads... and Shared Your Account Access - Twitch
The Twitch extension really did make streams better. That did not answer a separate question: what was it doing with users' account access? A useful feature and a security problem can exist at the same time.
Incident overview
Socket found that Twitch Enhanced Viewer, a third-party JeetBot extension, forwarded Twitch account tokens to its provider's servers. It had more than 30,000 installs across Chrome and Firefox. That is not a count of confirmed account thefts.
Why it works
When a tool fixes an annoying problem, we can feel good about the whole thing. Connor connects that reaction to the affect heuristic: liking the benefit can influence how small the risk feels, even without new evidence about safety.
Protective actions
- Ask two separate questions: does this help me, and am I comfortable with the access it needs?
- If you used this extension, check the dated fix information below. Stop using an affected version before signing back into Twitch.
- In Twitch's Security and Privacy settings, use Sign Out Everywhere, then sign back in. Fixing the extension and ending old sessions are separate steps.
Video companion
Watch the breakdown
The useful part was real
Fewer ads. Better video. You install the extension, the stream improves, and you get back to watching. That is the part you can see working.
The part you cannot see as easily is what happens to your account access along the way.
An account token is a credential a service uses to recognize an authorized session. It is not your password, but someone holding a valid token may be able to use the access it allows without typing that password. The permissions matter.
In this case, the problem was not just video passing through another server. Account credentials were going along with it.
What changed by September 16?
Socket verified that Firefox version 85.8.7 stopped forwarding the token. At the September 16 check, the same fix was awaiting Chrome Web Store review; Chrome version 85.8.4 still had the affected behavior.
For Firefox, update to the fixed version or a later release containing the fix. For Chrome, disable or remove the affected extension until a fixed release is available and verified. Check Socket's dated update for later developments.
The developer disputes malicious intent and says the tokens supported playback. The team acknowledged the security risk and inadequate disclosure. The cited report does not establish mass account theft, and this is not a breach of Twitch's own systems.
Helpful is one question. Safe is another.
Imagine a repair shop fixes your cracked phone screen beautifully, then keeps your passcode in a shared notebook. The repair can be excellent while the access handling still deserves a very different review. This is an analogy, not another reported incident.
That is the distinction behind Connor's affect heuristic angle. Our feelings about something can influence how we judge both its benefits and its risks. The tool feels helpful, so the whole situation starts to feel reassuring.
In a 2000 study, Finucane and colleagues gave participants information about the risks or benefits of technologies such as nuclear power. Information aimed at improving benefit judgments could also reduce perceived risk. That did not mean the technology itself had become safer.
The study did not test Twitch users or browser extensions. It offers a useful way to examine a judgment, not proof of why anyone installed this add-on.
Two jobs after an access problem
First, stop the affected software from sharing more access. Then deal with access it may already have shared. Updating alone is not the same as ending an existing session.
Open Twitch's security settings (opens in a new tab) yourself. Use Sign Out Everywhere, then sign back in after addressing the extension. If you see unfamiliar account activity, follow Twitch's account-recovery guidance (opens in a new tab).
For your next extension, check the permissions and remove add-ons you no longer use. Those habits cannot reveal every hidden problem. They can keep convenience from getting an automatic yes.
You can like what a tool does and still question the access it needs.
Sources
- Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service (opens in a new tab)
Socket · September 11, 2026
Supports: Technical findings and September 16 update verifying Firefox 85.8.7; Chrome fix pending review at that check.
- It Blocked Ads... and Shared Your Account Access - Twitch (opens in a new tab)
CyberPsych with Connor · September 16, 2026
Supports: Published title, date, developer-response context, psychology framing, and practical guidance. This article is not a verbatim transcript.
- Authentication (opens in a new tab)
Twitch Developers
Supports: Access tokens authorize actions within their permissions; they are not passwords or automatically unlimited account access.
- The affect heuristic in judgments of risks and benefits (opens in a new tab)
Journal of Behavioral Decision Making
Supports: Finucane and colleagues, 2000, Study 2. A study of risk and benefit judgments, not this extension's users.
Related cases
Video breakdownProve You're Human... Install This Malware - ClickFix
A familiar website check turns into a request to run a computer command. The trick depends on you treating a very different task like the same old interruption. You do not need to know code to know where to stop.
Video breakdownThousands of Leaked Cloud Keys Still Work... The AWS Access Key Problem
Thousands of AWS access keys found in public sources still opened the cloud accounts behind them. Removing a leaked key from view does not make the key stop working.
