Malicious Firefox Extensions Steal Crypto Wallets: 40 Confirmed Threats
TREE NEWS reports: Brief: Security firm Socket has uncovered a coordinated malicious campaign targeting Firefox users, identifying 77 extension identities linked by shared code, infrastructure, and release patterns. Of these, 40 have been confirmed as malicious, primarily impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. The extensions trick users into entering their recovery phrases, private keys, and other credentials, which are then stolen. Additionally, 37 other extensions disguised as password generators, VPNs, or dark mode tools were found running sports score apps, with 9 initially released as sports score tools before being updated to include wallet-stealing code.
Industry Analysis
This incident underscores the growing sophistication of supply-chain attacks targeting the crypto ecosystem. By impersonating trusted wallet brands, attackers exploit user trust and the convenience of browser-based access. The use of shared infrastructure and staged updates—first benign, then malicious—evades initial security reviews and allows the malware to persist before activation.
For users, the reliance on browser extensions for wallet management introduces a significant attack surface. Unlike hardware wallets or dedicated mobile apps, extensions operate within the browser’s security context, which can be compromised by malicious code. The fact that these extensions were available on Mozilla’s official add-on store—even temporarily—highlights the limitations of current review processes.
For developers and wallet providers, this is a reminder that brand reputation alone cannot protect users. There is an urgent need for more robust verification mechanisms, such as cryptographic signing of extensions, real-time monitoring for suspicious updates, and community-driven vetting. Additionally, wallet users should adopt a hierarchy of security: hardware wallets for long-term storage, software wallets with minimal permissions for active trading, and browser extensions only for read-only interactions or with extra caution.
Forward-Looking Perspective
As the crypto market matures, we can expect more targeted attacks on user endpoints, especially as institutional adoption grows. Regulatory bodies may begin to impose stricter security standards for browser extensions that handle digital assets. Meanwhile, the rise of decentralized identity and multi-party computation could offer new ways to protect users without compromising convenience.
In the short term, Firefox users should audit their installed extensions, remove any that are unfamiliar, and enable two-factor authentication wherever possible. Wallet providers should consider issuing security advisories and collaborating with browser vendors to improve extension vetting. Ultimately, this event serves as a critical reminder that in the decentralized world, personal security hygiene remains the last line of defense.



