Malicious Firefox Add‑ons Impersonate Crypto Wallets to Harvest Users’ Recovery Phrases
Security analysts have identified a suite of sixteen fraudulent extensions for Mozilla Firefox that are designed to capture the recovery phrases and private keys of cryptocurrency wallets. The malicious add‑ons pose as legitimate wallet portals, desktop utilities, and other browser tools, tricking users into exposing the credentials needed to control their digital assets.
According to the researchers, the extensions are distributed through the official Firefox Add‑Ons store, where they appear to offer services such as “Rabby” and “OKX” wallet access, as well as generic blockchain utilities. Once installed, the code silently monitors the browser for any input that resembles a seed phrase or private key, then transmits the data to command‑and‑control servers operated by the attackers.
The campaign appears to be coordinated, as the extensions share similar code patterns and use identical obfuscation techniques. Some of the add‑ons also request elevated permissions, including the ability to read and modify browsing data, which they leverage to inject counterfeit login pages into popular crypto sites. Users who enter their credentials on these spoofed pages inadvertently hand over the information to the threat actors.
Mozilla has responded by removing the offending extensions from its repository and issuing a warning to users to review their installed add‑ons. The company advises that any user who installed the flagged extensions should uninstall them immediately, change all compromised wallet credentials, and consider moving funds to new wallets generated with fresh recovery phrases.
The incident underscores the growing risk that browser extensions pose to cryptocurrency holders. While extensions can enhance browsing experience, they also gain deep access to a user’s online activity, making them attractive vectors for financial theft. Security experts recommend limiting the number of installed add‑ons, verifying developer identities, and only downloading extensions from trusted sources.
Looking ahead, researchers expect that cybercriminals will continue to exploit the popularity of decentralized finance by crafting more sophisticated masquerades. Ongoing monitoring of extension marketplaces and rapid takedown procedures will be crucial in mitigating future threats, as users increasingly rely on browsers to manage their crypto interactions.
Comments (0)
Be the first to comment.
Join the discussion