Press Enter to search · ESC to close

Crypto

Malicious Firefox Extensions Steal Crypto Wallets: 40 Confirmed Threats

Socket security firm identified 77 malicious Firefox extensions, with 40 confirmed stealing crypto wallet credentials by impersonating trusted brands like OKX and Rabby. The campaign uses shared infrastructure and staged updates to evade detection, highlighting the need for stronger extension vetting and user vigilance.

Malicious Firefox Extensions Steal Crypto Wallets: 40 Confirmed Threats

Brief: Security firm Socket has uncovered a coordinated malicious campaign targeting Firefox users, identifying 77 extension identities linked by shared code, infrastructure, and release patterns. Of these, 40 have been confirmed as malicious, primarily impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. The extensions trick users into entering their recovery phrases, private keys, and other credentials, which are then stolen. Additionally, 37 other extensions disguised as password generators, VPNs, or dark mode tools were found running sports score apps, with 9 initially released as sports score tools before being updated to include wallet-stealing code.

Industry Analysis

This incident underscores the growing sophistication of supply-chain attacks targeting the crypto ecosystem. By impersonating trusted wallet brands, attackers exploit user trust and the convenience of browser-based access. The use of shared infrastructure and staged updates—first benign, then malicious—evades initial security reviews and allows the malware to persist before activation.

For users, the reliance on browser extensions for wallet management introduces a significant attack surface. Unlike hardware wallets or dedicated mobile apps, extensions operate within the browser’s security context, which can be compromised by malicious code. The fact that these extensions were available on Mozilla’s official add-on store—even temporarily—highlights the limitations of current review processes.

For developers and wallet providers, this is a reminder that brand reputation alone cannot protect users. There is an urgent need for more robust verification mechanisms, such as cryptographic signing of extensions, real-time monitoring for suspicious updates, and community-driven vetting. Additionally, wallet users should adopt a hierarchy of security: hardware wallets for long-term storage, software wallets with minimal permissions for active trading, and browser extensions only for read-only interactions or with extra caution.

Forward-Looking Perspective

As the crypto market matures, we can expect more targeted attacks on user endpoints, especially as institutional adoption grows. Regulatory bodies may begin to impose stricter security standards for browser extensions that handle digital assets. Meanwhile, the rise of decentralized identity and multi-party computation could offer new ways to protect users without compromising convenience.

In the short term, Firefox users should audit their installed extensions, remove any that are unfamiliar, and enable two-factor authentication wherever possible. Wallet providers should consider issuing security advisories and collaborating with browser vendors to improve extension vetting. Ultimately, this event serves as a critical reminder that in the decentralized world, personal security hygiene remains the last line of defense.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback