Forty malicious Firefox wallet extensions impersonating major wallets harvest user recovery phrases and steal crypto.
Security & Exploits ·
Security researchers linked 77 Firefox extension identities to a coordinated campaign and confirmed 40 as malicious, with the extensions impersonating OKX, Rabby Wallet, and TronLink to steal recovery phrases and private keys. The malicious add-ons operated from March 9 to August 3, with some beginning as legitimate sports-score applications before being updated to wallet-stealing malware that inherited their install bases and review histories. About half presented fake wallet interfaces to harvest credentials typed by users, while others captured stored account data or clipboard contents; nine extensions transitioned from sports apps to wallet theft through code updates. Users who entered recovery phrases or private keys into these extensions should move funds immediately, as uninstalling the malware does not revoke already-compromised credentials.