BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GreedyBear Malware Uses Fake Firefox Wallet Extensions to Steal $1M

  • A campaign using over 150 fake Firefox extensions stole more than $1 million in cryptocurrency.
  • The attackers copied popular crypto wallets to trick users and steal credentials.
  • Malicious extensions bypassed security by starting as harmless apps, then adding harmful features later.
  • The threat expands beyond Firefox, with similar attacks noted on Chrome and through scam sites.
  • AI tools helped the attackers scale up, while related scams also used fake trading bots on YouTube to steal Ethereum.

A large-scale cyber campaign named GreedyBear has used more than 150 fraudulent browser extensions on the Firefox extension store to steal over $1 million in cryptocurrency. Attackers created fake versions of well-known crypto wallets—like MetaMask, TronLink, Exodus, and Rabby Wallet—to access credentials and digital assets.

- Advertisement -

According to Koi Security researcher Tuval Admoni, the attackers developed extensions that appeared trustworthy, using a method called “Extension Hollowing.” In this approach, they first released non-malicious browser add-ons to pass security checks before quietly adding malicious code later. The extensions collected users’ wallet credentials and IP addresses, forwarding the data to servers controlled by the group.

Rather than trying to sneak malicious extensions past initial reviews, they build legitimate-seeming extension portfolios first, then weaponize them later when nobody’s watching, Admoni stated in a published report. The group’s earlier campaign used at least 40 similar extensions under the name Foxy Wallet, but the current activity marks a much larger operation.

Attackers didn’t limit their reach to browser add-ons. They also spread Malware through pirated software websites and created scam sites imitating crypto services to steal more credentials. All three types of attacks were linked by a shared command-and-control server with the IP address 185.208.156[.]66, used for gathering stolen data.

Koi Security also found signs that the attackers may have leveraged Artificial Intelligence tools in their operations, helping them broaden their campaign and adapt tactics. The malicious activity has reached other browsers, including a Chrome extension called Filecoin Wallet, which used the same data theft patterns.

- Advertisement -

Meanwhile, security company SentinelOne reported a separate, related scam involving fake trading bots promoted on YouTube. These videos, mostly produced by AI, instructed viewers to deploy malicious Ethereum smart contracts, resulting in over $900,000 in stolen cryptocurrency. Accounts pushing these scams were often established and featured curated positive feedback to gain users’ trust.

Victims who followed these steps had their Ethereum rerouted to the scammers’ wallets, demonstrating how attackers exploit trust across multiple digital platforms for financial theft.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

RaveDAO Denies Manipulation as Exchanges Probe Token Plunge

RaveDAO has denied responsibility for its RAVE token's extreme price volatility following allegations of...

Robinhood Soars 31% on SEC Rule Change and Crypto Rally

Robinhood (HOOD) stock surged 31% this week, making it the top performer in the...

Bitcoin Eyes $82K by April’s End Amid Volatility

Analysts predict a final push for Bitcoin towards the $78,000-$80,000 zone before a potential...

Worldcoin Drops 13% Despite Zoom, Docusign ID Deals

Worldcoin (WLD) dropped 13.4% to roughly $0.28 on Friday, contrasting with a broader crypto...

Bitcoin Soars Past Key Resistance; Traders See 69% Chance of $84K

Bitcoin surged 2.7%, breaking a key descending resistance line that had suppressed its price...

Must Read

7 Best NFT Marketplaces for Every Need

Open Sea | Pianity | Foundation | Magic Eden | SuperRare | Rarible | Theta Drop | Other Platforms | About NFTs | FAQ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading