Back to all lessons
Awareness Lessons
2 months ago

40 Fake Web3 Firefox Extensions Harvest Crypto Wallet Secrets

Attackers deployed 40 malicious Firefox extensions impersonating trusted Web3 brands like OKX and Rabby Wallet to trick users into installing credential-stealing software. Once installed, these extensions silently exfiltrated recovery phrases and private keys — the master credentials for cryptocurrency wallets — through legitimate-looking cloud infrastructure (Supabase and Cloudflare Workers) to evade detection. This attack exploits user trust in well-known brand names and the relative openness of browser extension ecosystems. Because cryptocurrency transactions are irreversible, victims have no recourse once wallet secrets are stolen. The campaign's scale — 77 coordinated add-ons sharing code and infrastructure — signals a sophisticated, ongoing threat actor rather than opportunistic fraud.

Tactical Insight

Immediate actions

  • Audit all currently installed browser extensions and remove any that are unverified, recently installed, or not sourced directly from official project websites.
  • Verify extension authenticity by cross-referencing the official publisher name, extension ID, and download count on the add-on marketplace before installing anything.

Long-term improvements

  • Implement an organizational policy that restricts browser extension installations to an approved allowlist managed by IT or security teams.
  • Store cryptocurrency wallet recovery phrases and private keys exclusively in hardware wallets or air-gapped offline storage, never in browser-accessible environments.
  • Treat any browser extension requesting access to clipboard, storage, or network communications as high-risk and subject it to formal review before approval.

Detection measures

  • Monitor outbound network traffic for unexpected connections to Supabase projects, Cloudflare Workers, or other third-party cloud endpoints that are not part of normal business operations.
  • Subscribe to threat intelligence feeds that track malicious browser extensions and automatically alert users or block known malicious extension IDs at the endpoint level.