Back to all lessons
Awareness Lessons
3 days ago

16 Fake Firefox Extensions Drain Crypto Wallets via Credential Theft

Attackers published 16 malicious Firefox extensions that convincingly impersonated trusted cryptocurrency wallets (Rabby and OKX), exploiting users' trust in browser extension marketplaces as a supply chain attack vector. The extensions silently intercepted seed phrases and private keys during wallet import flows, then exfiltrated them to attacker-controlled infrastructure — giving threat actors full control over victims' funds. This incident highlights that browser extension stores, despite vendor review processes, remain a viable and dangerous supply chain risk. Because private keys and recovery phrases are irrevocable, any compromise is permanent and irreversible without migrating assets immediately. Users who lack the awareness to verify extension authenticity are especially vulnerable to these impersonation campaigns.

Tactical Insight

Immediate actions

  • Audit all installed browser extensions and remove any cryptocurrency-related extensions not verified directly from the official wallet developer's website.
  • If you imported a wallet while a suspicious extension was installed, immediately create a new wallet from a clean, extension-free environment and transfer all assets.
  • Report any suspect extensions to Mozilla's Add-on Security team and your organization's security team.

Long-term improvements

  • Enforce a policy of only installing browser extensions from verified, allowlisted sources and require secondary verification (e.g., matching publisher signing certificates or official developer links).
  • Train users to recognize extension impersonation tactics, including how to cross-reference extension publisher identity against official project websites and GitHub repositories.
  • Implement MDM or browser management policies in enterprise environments to restrict unauthorized extension installation.

Detection measures

  • Monitor endpoint security tools and browser telemetry for extensions making unexpected outbound network requests to external domains (e.g., Cloudflare Workers endpoints not associated with legitimate services).
  • Subscribe to threat intelligence feeds that surface malicious or newly flagged browser extensions relevant to cryptocurrency and financial tooling.
  • Establish a regular cadence (monthly) for reviewing and re-validating all installed browser extensions across managed devices.