Cybersecurity researchers have uncovered 16 malicious Firefox browser extensions designed to steal cryptocurrency wallet recovery phrases and private keys. The extensions impersonated popular crypto wallets and legitimate browser utilities, potentially putting users’ digital assets at risk.
According to security company Socket, the campaign primarily targeted users of Rabby Wallet and OKX Wallet. The attackers created convincing copies of these services, making the extensions appear to be legitimate tools for accessing or managing cryptocurrency.
Four of the extensions imitated Rabby Wallet, while another 12 were designed to resemble OKX Wallet. Some used slightly altered names and familiar-looking interfaces to deceive users searching for genuine wallet software.
Socket researchers discovered that the extensions intercepted sensitive information when users attempted to import an existing cryptocurrency wallet. During this process, victims could be asked to enter their recovery phrase, typically a sequence of 12 or 24 words used to restore access to their funds.
Instead of keeping this information private, the malicious extensions attempted to transmit it to servers controlled by the attackers. Socket found that the campaign used Cloudflare Workers infrastructure to receive stolen wallet credentials.
The researchers also identified an important inconsistency in the extensions’ permissions. Although all 16 declared that they collected no user data, their underlying code contained functions designed to capture and transmit cryptocurrency wallet secrets.
Not every extension was fully operational. Socket identified one version containing credential-stealing code that could not function as intended because of programming errors. The remaining variants included working mechanisms for extracting sensitive information.
Socket believes the operation is connected to a larger campaign uncovered in August 2026, when researchers identified dozens of suspicious Firefox extensions associated with cryptocurrency theft. Similarities in their code, infrastructure, and distribution methods suggest the attackers continued adapting their approach.
Mozilla removed the newly identified malicious extensions from publication by October 5. However, removing an extension does not make a previously exposed recovery phrase secure.
Socket warns that anyone who entered a genuine recovery phrase or private key into one of the functioning malicious extensions should consider that wallet compromised. Affected users should create a new wallet in a clean environment and transfer their cryptocurrency to it as soon as possible.
The researchers also recommend installing wallet extensions only through verified official sources and carefully checking their names and publishers. Even extensions with limited permissions or reassuring privacy declarations can conceal dangerous functionality.
