
40 Malicious Firefox Extensions Impersonate Crypto Wallets, Harvest Recovery Phrases
Security researchers identified 40 malicious Firefox add-ons impersonating popular wallet extensions including OKX, Rabby, and TronLink to steal recovery phrases from users. Nine of the malicious extensions began as sports-score tools before pivoting to credential harvesting, and exposed wallets may require migration even after removal.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Campaign and Scope
Security firm Socket confirmed 40 malicious Firefox add-ons designed to impersonate legitimate cryptocurrency wallet extensions, according to reporting from both Decrypt and CryptoSlate. The fake extensions targeted three named wallet projects: OKX, Rabby, and TronLink. The extensions functioned as credential-harvesting malware, capturing recovery phrases typed by users who believed they were interacting with authentic wallet software.
How the Attack Evolved
Nine of the 40 malicious add-ons originated as sports-score utilities before being repurposed for wallet impersonation, according to CryptoSlate's reporting. This suggests attackers either compromised existing extensions with user bases and changed their functionality, or used legitimate sports-score tools as a Trojan horse to establish distribution channels before pivoting to financial theft.
Remediation and Residual Risk
Removing the malicious extensions from a browser does not fully resolve the security breach. CryptoSlate reported that wallets with exposed recovery phrases may still require migration to new addresses, since an attacker holding a recovery phrase can access funds indefinitely. Users who installed any of the 40 extensions should treat affected wallets as compromised and move funds immediately.
Why It Matters
For Traders
Check Firefox extension lists for OKX, Rabby, or TronLink wallets installed; if present, assume recovery phrase is compromised and migrate funds to a new address immediately.
For Investors
High-friction social engineering remains a structural security gap in custodial and self-custody wallet adoption; projects need clearer in-browser authentication UI to prevent impersonation.
For Builders
Wallet teams should consider distributing browser extensions only through official package registry verification or signed app stores rather than open Firefox marketplaces.
This article is for information only and is not financial advice. Read the full disclaimer.






