16 Malicious Firefox Extensions Target Cryptocurrency Wallets
In a concerning development for cryptocurrency users, a report by Socket has unveiled the existence of 16 malicious Firefox extensions masquerading as legitimate cryptocurrency wallets. These deceptive extensions aim to intercept recovery phrases and private keys during wallet imports, posing a significant threat to users’ digital assets.
The malicious extensions are cleverly disguised as wallet portals, desktop utilities, and browser tools, attempting to transmit sensitive information to attacker-controlled Cloudflare Workers. This alarming tactic highlights the increasingly sophisticated methods employed by cybercriminals to exploit the growing user base of cryptocurrency wallets.
Mozilla’s Rapid Response
In response to these findings, Mozilla acted swiftly to protect its users by removing these harmful extensions from its platform. By October 5, 2026, a decisive action was taken to unpublish the extensions, but the potential damage may have already been done. The Socket report reveals that out of the 16 extensions identified, 15 contained active collection handlers designed to harvest sensitive data. Only one extension presented implementation defects that inhibited its ability to effectively execute its malicious intended functions.
Each of the extensions presented a manifest that falsely declared permission for data collection as "none," an outright contradiction to the embedded code responsible for transmitting stolen recovery phrases and private keys. This demonstrates a glaring disconnect between the displayed permissions and the invasive actions these extensions were capable of performing.
Deceptive Branding Techniques
Among the malicious extensions, those imitating the Rabby Wallet were particularly notable. They bore the misleading name “Raabby WaIIet” and contained an extensive range of files—1,114 in total—that included wallet keyrings, import screens, transaction interfaces, and Webpack components. This extensive functionality allowed the malicious versions to blend seamlessly into the user experience, making them less conspicuous than a typical phishing form.
The attackers utilized official Rabby links and retained DeBank assets to reinforce their impersonation. Within the injected background.js file, a helper function was embedded, designed to accept either a 12-word or 24-word recovery phrase along with a 64-character hexadecimal private key. This technical detail underscores the calculated approach taken by the attackers to extract sensitive information while maintaining a facade of legitimate wallet functions.
Advanced Data Collection Techniques
Intriguingly, the malicious code was structured to allow routine operations to proceed while simultaneously capturing sensitive details. Calls were inserted after actions such as importPrivateKey and createKeyringWithMnemonics, ensuring that legitimate wallet functionalities remained uninterrupted. Additionally, additional hooks embedded in a file identified as 977.js were tasked with gathering secrets during frontend import processes, showcasing the attackers’ meticulous approach to data collection.
Socket researchers have identified that the campaign encompasses four modified Rabby Wallet applications and twelve compact extensions utilizing designs derived from OKX interfaces. The stolen recovery phrases and private keys are transmitted as parameters via HTTPS GET requests to a specified endpoint controlled by the attackers.
Consequences and User Precautions
Users are urged to exercise extreme caution. The report details that those who unwittingly submitted sensitive information should consider their wallets compromised. It is imperative that these users promptly uninstall the malicious extensions, create new wallets in a secure environment, and transfer their digital assets immediately. As a crucial point, merely changing the password on an extension won’t mitigate risks associated with exposed recovery phrases or private keys.
The campaign, which continues to evolve, has connections to a prior investigation by Socket, which tracked 77 related extensions. Out of these, 40 were confirmed as malicious, while another 37 were linked to deceptive sports-score shells. The shared infrastructure, common coding practices, and specific campaign markers solidify this latest operation as a continuation of earlier threats.
Defensive Measures and Further Research
As a proactive defense strategy, cybersecurity professionals are encouraged to consult the report’s inventory of affected extensions along with indicators to identify and mitigate risks associated with these ongoing threats. Additionally, telemetry data should be scrubbed of sensitive information to prevent exposure of already stolen secrets. It’s also worth noting that legitimate domains associated with Rabby and DeBank are not indicators of malicious intent; rather, broad permissions alone do not inherently signal additional browsing data theft.
In conclusion, this incident serves as a stark reminder of the ever-present risks within the cryptocurrency domain. Users must remain vigilant, ensuring they utilize trusted sources and continuously educate themselves on security practices to safeguard their assets against evolving cyber threats.

