BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Over 40 Malicious Firefox Extensions Steal Crypto Wallet Secrets

Over 40 Malicious Firefox Extensions Impersonate Crypto Wallets, Steal User Data

  • Researchers found more than 40 harmful Firefox extensions designed to steal cryptocurrency wallet secrets.
  • The fake extensions imitated trusted wallet tools from companies like Coinbase, MetaMask, and others.
  • The malicious add-ons used fake five-star reviews and copied branding to appear authentic to users.
  • The campaign, active since at least April 2025, primarily targeted users by taking information directly from browser activity.
  • Mozilla has removed nearly all involved extensions and introduced new detection measures, but users are advised to verify extensions before installation.

Cybersecurity researchers have identified over 40 malicious browser extensions in the Mozilla Firefox Add-ons store that steal cryptocurrency wallet information. The campaign, which started by April 2025 at the latest, involved extensions impersonating legitimate crypto wallet tools to obtain sensitive user data.

- Advertisement -

These extensions posed as authentic add-ons for platforms such as Coinbase, MetaMask, Trust Wallet, and others, according to Koi Security researcher Yuval Ronen. Attackers uploaded new malicious versions as recently as last week, while boosting the extensions’ perceived popularity with hundreds of fake, five-star reviews. These reviews far outnumbered actual user installations, making the add-ons appear reputable.

“These extensions impersonate legitimate wallet tools from widely-used platforms such as Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox,” Ronen wrote in a detailed analysis. Attackers often cloned open-source versions of real extensions, adding their own code to steal wallet keys and seed phrases. The malicious software also collected victims’ external IP addresses and sent the data to attackers’ remote servers.

These add-ons worked directly inside the browser instead of using phishing websites or misleading emails. This made them more difficult for standard antivirus or anti-phishing tools to detect. “This low-effort, high-impact approach allowed the actor to maintain expected user experience while reducing the chances of immediate detection,” Ronen explained.

Investigators found Russian-language notes in the source code, as well as evidence from a server used by the campaign, suggesting a Russian-speaking group was behind the operation.

- Advertisement -

Mozilla has removed all affected extensions except for one linked to MyMonero Wallet. The company has also started using a new early detection system to spot scam crypto wallet extensions before they are widely downloaded.

Experts recommend that users only install extensions from verified publishers and monitor add-ons for suspicious changes.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Pump.fun’s GO Bounty Platform Pays for Wild Stunts

Pump.fun launched its GO bounty platform, allowing users to pay for "ANY task" and...

Everest Forms Pro Bug Exploited, Sites Hacked

A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively...

Kotak Sets Bajaj Housing Finance Target At ₹105

Kotak Securities has assigned a 12-month price target of 105 to Bajaj Housing Finance...

U.S. Eyes Stake In AI Firms Like OpenAI

The U.S. government is reportedly discussing a plan for AI firms to voluntarily cede...

Senate GOP urges US regulators to ease crypto bank rules

Senator Cynthia Lummis led a group of Republican senators in sending a letter to...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading