40 Malicious Firefox Extensions Impersonate Crypto Wallets, Harvest Recovery Phrases
SecurityExchanges
Bearish

40 Malicious Firefox Extensions Impersonate Crypto Wallets, Harvest Recovery Phrases

Security researchers identified 40 malicious Firefox add-ons impersonating popular wallet extensions including OKX, Rabby, and TronLink to steal recovery phrases from users. Nine of the malicious extensions began as sports-score tools before pivoting to credential harvesting, and exposed wallets may require migration even after removal.

Aug 26, 2026, 05:09 AM1 min read

Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work

The Campaign and Scope

Security firm Socket confirmed 40 malicious Firefox add-ons designed to impersonate legitimate cryptocurrency wallet extensions, according to reporting from both Decrypt and CryptoSlate. The fake extensions targeted three named wallet projects: OKX, Rabby, and TronLink. The extensions functioned as credential-harvesting malware, capturing recovery phrases typed by users who believed they were interacting with authentic wallet software.

How the Attack Evolved

Nine of the 40 malicious add-ons originated as sports-score utilities before being repurposed for wallet impersonation, according to CryptoSlate's reporting. This suggests attackers either compromised existing extensions with user bases and changed their functionality, or used legitimate sports-score tools as a Trojan horse to establish distribution channels before pivoting to financial theft.

Remediation and Residual Risk

Removing the malicious extensions from a browser does not fully resolve the security breach. CryptoSlate reported that wallets with exposed recovery phrases may still require migration to new addresses, since an attacker holding a recovery phrase can access funds indefinitely. Users who installed any of the 40 extensions should treat affected wallets as compromised and move funds immediately.

Why It Matters

For Traders

Check Firefox extension lists for OKX, Rabby, or TronLink wallets installed; if present, assume recovery phrase is compromised and migrate funds to a new address immediately.

For Investors

High-friction social engineering remains a structural security gap in custodial and self-custody wallet adoption; projects need clearer in-browser authentication UI to prevent impersonation.

For Builders

Wallet teams should consider distributing browser extensions only through official package registry verification or signed app stores rather than open Firefox marketplaces.

This article is for information only and is not financial advice. Read the full disclaimer.

Related Articles

Latest News