Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Wallets

Fake Firefox Wallet Extensions Target Crypto Credentials

2 reports · First detected 2026-08-25 · Last active 2026-08-26

Crypto wallet seed phrases and credentials give holders direct control over digital assets, making browser extensions an attractive target for credential theft. Security firm Socket said attackers exploited the Firefox add-on ecosystem by impersonating well-known wallets including OKX, Rabby Wallet and TronLink, using familiar branding and interfaces to persuade users to enter sensitive recovery information.

Socket identified 77 suspicious Firefox extensions in the latest campaign, with 40 confirmed to contain functionality designed to steal wallet secrets. The add-ons harvested seed phrases and credentials through counterfeit wallet interfaces or maliciously altered code. Some extensions used a delayed-switch tactic: they initially appeared as legitimate sports-score tools, then received updates that transformed them into crypto-stealing malware.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)