• 4 mins read
  • Published

Malicious Firefox Add-Ons Compromise Crypto Wallets in Targeted Attack

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Malicious Firefox Add-Ons Compromise Crypto Wallets in Targeted Attack EgonCoin © egoncoin.com
Malicious Firefox Add-Ons Compromise Crypto Wallets in Targeted Attack © egoncoin.com

Dozens of Firefox browser extensions were found stealing crypto wallet secrets, forcing affected users to abandon compromised wallets and migrate funds. The campaign highlights ongoing risks for browser-based wallet security

A recent investigation by software supply-chain security firm Socket has uncovered a coordinated campaign involving 40 malicious Firefox browser add-ons designed to steal cryptocurrency wallet secrets. The campaign, which operated for at least five months, targeted users by distributing extensions that captured sensitive wallet information, including recovery phrases and private keys. Nine of the malicious add-ons were previously distributed as sports-score tools, repurposed under the same extension identities to evade detection.

How the Attack Worked

According to Socket, the malicious add-ons used a variety of attack methods. Some acted as remote-controlled phishing loaders, while others directly harvested wallet recovery phrases, private keys, or serialized keyrings-data that can be used to restore or take control of a wallet. Thirteen of the extensions were modified clones of the Rabby wallet, a popular browser-based crypto wallet, and were engineered to transmit keyring data before local encryption could protect it. Additional add-ons collected user credentials and clipboard data, potentially exposing passwords and copied wallet addresses.

User Impact and Required Actions

For users whose wallet secrets were exposed to these add-ons, uninstalling the extension is not enough to secure their assets. Once a recovery phrase or private key has been compromised, the only safe course is to migrate funds to a new wallet generated from a fresh recovery phrase. Users affected by add-ons that captured only credentials or clipboard data should change passwords, terminate active sessions, and verify any copied addresses before making further transactions. Socket emphasized that any wallet whose secret or keyring was transmitted by a malicious extension should be considered permanently compromised.

Mozilla's Response and Ongoing Risks

Socket's report noted that several of the malicious add-ons remained available on the Firefox Add-ons Marketplace at the time of discovery. Mozilla, which uses a combination of automated risk indicators and human review to screen wallet extensions, removed the identified add-ons after being notified. The campaign, provisionally named the "Offside Wallet Theft Factory," was linked to 77 extension identities, with 40 confirmed as malicious and 37 flagged as suspicious but not conclusively tied to theft. The malicious extensions were active from at least March through early August, with activity peaking in April and late July.

Scale and Detection Challenges

Socket documented the technical infrastructure used for exfiltrating stolen wallet data but did not identify specific victims or quantify the total losses. The firm's analysis relied on Mozilla's signing records, which showed that the original 59 versions of the extensions were signed between March 9 and August 3. The incident underscores the persistent risks associated with browser-based crypto wallets and the importance of installing extensions only from official wallet provider sites. While Mozilla has removed the known malicious add-ons, the evolving tactics used by attackers highlight the need for ongoing vigilance among users and developers alike.

According to Mozilla's public extension data, the remote-controlled phishing add-on "0KX WEB3" was still live with seven users at the time of Socket's analysis, but was removed before the report's publication. No confirmed victim addresses or attributable theft transactions have been publicly disclosed as of this writing.

Browser-based crypto wallets remain a popular target for attackers due to their accessibility and the sensitive information they handle. Unlike hardware wallets, which store private keys offline, browser extensions are exposed to a broader range of threats, including malicious add-ons, phishing, and clipboard hijacking. Users should be cautious when installing wallet-related extensions, verify sources, and regularly review wallet security practices to reduce the risk of compromise.

Related articles