Fake Firefox Wallet Extensions Target Crypto Credentials
Crypto wallet seed phrases and credentials give holders direct control over digital assets, making browser extensions an attractive target for credential theft. Security firm Socket said attackers exploited the Firefox add-on ecosystem by impersonating well-known wallets including OKX, Rabby Wallet and TronLink, using familiar branding and interfaces to persuade users to enter sensitive recovery information.
Socket identified 77 suspicious Firefox extensions in the latest campaign, with 40 confirmed to contain functionality designed to steal wallet secrets. The add-ons harvested seed phrases and credentials through counterfeit wallet interfaces or maliciously altered code. Some extensions used a delayed-switch tactic: they initially appeared as legitimate sports-score tools, then received updates that transformed them into crypto-stealing malware.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →