Security researchers have uncovered a cluster of 16 malicious Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys. The extensions impersonate legitimate wallet brands, including Rabby and OKX, along with other wallet portals, desktop utilities, and general browser tools.
According to the findings, the malicious code embedded in these extensions is built to intercept sensitive data during the wallet import process, specifically targeting the moment users enter their seed phrases or private keys to restore or connect a wallet. Once captured, the extensions attempt to exfiltrate these secrets to attacker-controlled infrastructure.
How the Scam Works
By mimicking trusted wallet brands and common browser utilities, the extensions aim to lower user suspicion and blend into the Firefox Add-ons ecosystem. Victims who install one of these fake tools and proceed to import an existing wallet risk handing over the recovery phrase that controls access to their crypto holdings, a single point of failure that typically cannot be reset or revoked once compromised.
Because recovery phrases and private keys grant full control over associated wallets, their theft can lead to irreversible loss of funds. Unlike passwords, these credentials cannot be rotated after exposure, making prevention the only effective defense.
Recommendations for Users
- Avoid installing wallet-related browser extensions unless they come directly from the official vendor’s verified listing or website.
- Never enter a seed phrase or private key into a browser extension unless you are certain of its authenticity.
- Review installed Firefox extensions regularly and remove any unfamiliar or unused add-ons, particularly those claiming to be wallet portals or desktop utilities.
- Use hardware wallets for storing significant crypto holdings, since they keep private keys isolated from browser-based attack surfaces.
- Report suspicious extensions to Mozilla’s add-on review team to help accelerate takedown efforts.
This discovery underscores a persistent trend of threat actors abusing browser extension marketplaces to target cryptocurrency users, who remain a high-value target due to the direct financial gain available from a single successful compromise.
