40 Fake Web3 Firefox Extensions Harvest Crypto Wallet Secrets
Attackers deployed 40 malicious Firefox extensions impersonating trusted Web3 brands like OKX and Rabby Wallet to trick users into installing credential-stealing software. Once installed, these extensions silently exfiltrated recovery phrases and private keys — the master credentials for cryptocurrency wallets — through legitimate-looking cloud infrastructure (Supabase and Cloudflare Workers) to evade detection. This attack exploits user trust in well-known brand names and the relative openness of browser extension ecosystems. Because cryptocurrency transactions are irreversible, victims have no recourse once wallet secrets are stolen. The campaign's scale — 77 coordinated add-ons sharing code and infrastructure — signals a sophisticated, ongoing threat actor rather than opportunistic fraud.
Tactical Insight
Immediate actions
- Audit all currently installed browser extensions and remove any that are unverified, recently installed, or not sourced directly from official project websites.
- Verify extension authenticity by cross-referencing the official publisher name, extension ID, and download count on the add-on marketplace before installing anything.
Long-term improvements
- Implement an organizational policy that restricts browser extension installations to an approved allowlist managed by IT or security teams.
- Store cryptocurrency wallet recovery phrases and private keys exclusively in hardware wallets or air-gapped offline storage, never in browser-accessible environments.
- Treat any browser extension requesting access to clipboard, storage, or network communications as high-risk and subject it to formal review before approval.
Detection measures
- Monitor outbound network traffic for unexpected connections to Supabase projects, Cloudflare Workers, or other third-party cloud endpoints that are not part of normal business operations.
- Subscribe to threat intelligence feeds that track malicious browser extensions and automatically alert users or block known malicious extension IDs at the endpoint level.