Keyboard shortcuts

Aug 27, 2026, 07:35 PM UTC
DeFi // Security

40 Fake Firefox Wallet Extensions Caught Stealing Seed Phrases — Some Spent Months Posing as Sports Apps

Socket researchers linked 77 extension identities to one campaign that impersonated OKX, Rabby, and TronLink — with sleeper apps converted into malware by update.

The Latest Desk
Aggregated
Aug 25, 2026, 02:10 PM UTC2 min read
40 Fake Firefox Wallet Extensions Caught Stealing Seed Phrases — Some Spent Months Posing as Sports Apps
SourceDecrypt· 2d ago

Security researchers at Socket have mapped a production line of counterfeit crypto wallet extensions targeting Firefox users — 77 extension identities linked by shared code, infrastructure, and publishing patterns, of which 40 are confirmed malicious. Mozilla's signing records date the campaign from March 9 to August 3, and several extensions were still live when Socket reported them.

The fakes impersonate OKX, Rabby Wallet, TronLink, and other Web3 products, often with lookalike characters close enough to pass a glance in the add-ons store.

Three flavors of theft

Roughly half the malicious extensions present a convincing wallet interface and simply ask users to import an existing wallet — harvesting whatever recovery phrase or private key is typed in. Another 13 are modified builds of the real Rabby wallet that behave normally while quietly exporting stored account data to an outside server. Five more skip the wallet pretense and collect saved credentials and clipboard contents.

The most patient trick: nine extensions began life as innocuous apps showing live football scores, built reputation and installs for months, then were converted into wallet malware by update. Another 37 identities posed as password generators, VPNs, dark-mode toggles, and note-taking tools — a warehouse of shells ready for the same conversion.

The defense that still works

Extension-store trust signals — age, install counts, reviews — are exactly what this campaign farmed, which makes them worthless as a defense here. The advice that survives: install wallets only from links on the project's own site, treat any extension that asks for a seed-phrase import as hostile until proven otherwise, and keep meaningful funds behind a hardware signer that a browser extension cannot reach. A seed phrase typed into the wrong box is not a mistake you get to undo.

Written by
The Latest Desk
Aggregated · @thelatest
Share

Discussion

0 comments
0/2000

No comments yet — be the first to weigh in.

More from peatpost