TechNewsReel
Live

40 Fake Crypto Wallet Extensions Found on Firefox Add-ons Store

Malicious extensions impersonating OKX, Rabby, and TronLink were used to harvest seed phrases from unsuspecting users.

TechNewsReel Newsroom · August 25, 2026

Dozens of malicious browser extensions have been discovered on the Firefox Add-ons store, designed to steal cryptocurrency from users. At least 40 of these extensions are confirmed to be malicious, specifically targeting individuals using popular non-custodial wallets.

The malware operates by impersonating well-known wallet providers, including OKX, Rabby, and TronLink. Once installed, the extensions present fake interfaces that prompt users to enter their seed phrases and recovery keys. According to reports from Decrypt, these credentials are then harvested by the attackers, granting them full and immediate control over the victims' digital assets.

The Trust Gap in Extension Stores

This campaign leverages a common vulnerability in the browser ecosystem: the inherent trust users place in official extension marketplaces. Many users assume that the presence of a tool in a curated store implies a rigorous vetting process. By mimicking the branding and functionality of legitimate wallet providers, attackers can bypass a user's natural skepticism, tricking them into handing over the most sensitive security credentials in the crypto ecosystem.

Why Recovery Phrase Theft is Critical

For users of non-custodial wallets, the recovery phrase is the ultimate key to their funds. Unlike traditional banking, where a lost password can be reset via identity verification, the loss of a seed phrase to a malicious actor results in an irreversible transfer of ownership. These "phishing-as-an-extension" attacks are particularly devastating because they do not require complex system exploits; they rely on social engineering to convince the user to voluntarily surrender their keys.

What to Watch

Security researchers continue to monitor the Firefox Add-ons store for similar impersonation tactics. While the 40 confirmed extensions have been identified, the incident underscores a broader systemic risk where malicious actors frequently rotate through different names and versions to evade detection. Users are advised to verify the developer and official documentation of any wallet extension before installation and to never enter a recovery phrase into a browser-based prompt unless they are absolutely certain of the software's authenticity.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.