Malicious Firefox Add-Ons Steal Crypto Wallet Keys and Recovery Phrases

1 hour ago 2 sources neutral

Key takeaways:

  • Browser extension attacks underscore persistent need for hardware wallets and verified downloads.
  • Repurposed benign add-ons show sophisticated social engineering targeting crypto users' wallet secrets.
  • Market impact likely limited; focus on security hygiene rather than price direction.

Software supply-chain security firm Socket identified 40 malicious Firefox add-on identities built to target cryptocurrency wallets, with nine of them beginning as benign sports-score tools before being repurposed. The report, published on Aug. 19, linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 showing confirmed malicious behavior and 37 remaining deceptive or suspicious sports-score shells without confirmed theft payloads.

The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July. Among the nine identities that shifted from sports utilities to malicious versions, examples included bright-save-feed@tabtools.org moving from Quick 7.4.0 to Rabbit For Desktop 8.20.10, and swift-clip-link@fasttools.co moving from Dial Open Pro 7.23.25 to Web3 & EVM 9.50.10. Other IDs followed similar patterns, repackaging names such as Quick Shield, Lite Swatch, Key Pulse, Timer Pulse and Pomodoro Plus into Rabbit or WALLET variants.

Socket classified the 40 malicious identities into distinct attack paths. Seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data. The report warned that a recovery phrase or private key can restore a wallet elsewhere, while a serialized keyring exposes the wallet’s account state before encryption can protect it. Anyone who entered secrets or used an affected build that transmitted its keyring should move remaining assets to a fresh wallet created from a new recovery phrase. Users exposed only to credential and clipboard collection should change affected passwords, terminate active sessions where possible, and verify copied destination addresses.

Socket noted that several campaign add-ons were still live when reported to Mozilla. The remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication. Mozilla said it uses automated risk indicators and human review to identify malicious wallet add-ons and advises users to install only extensions linked from a wallet provider’s official site. The research documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a total campaign loss. The disclosure is being treated as a security event rather than a market or valuation signal.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.