By Interestana AI Editorial — AI-drafted, human-overseen. How we report
16 Malicious Firefox Extensions Steal Crypto Wallet Secrets

Cybersecurity researchers have identified a significant threat targeting cryptocurrency users through the Mozilla Firefox browser, uncovering 16 malicious extensions designed to steal sensitive wallet information. These extensions, discovered by researchers at Trust Wallet, masquerade as legitimate wallet portals, desktop utilities, and general browser tools. Their primary objective is to intercept and exfiltrate users' cryptocurrency recovery phrases and private keys, particularly during wallet import processes. The malicious code within these extensions is engineered to capture these critical credentials and transmit them to remote servers controlled by the attackers. This discovery highlights an ongoing and evolving threat landscape for digital asset holders who rely on browser-based extensions for managing their portfolios.
The identified extensions impersonate popular cryptocurrency wallet services and related tools, aiming to gain user trust and facilitate the theft of recovery phrases, which are essentially the master keys to a user's cryptocurrency holdings. Recovery phrases, typically a sequence of 12 or 24 words, are vital for restoring access to a crypto wallet if a device is lost or damaged. If an attacker obtains this phrase, they can gain complete control over the associated wallet and all the digital assets within it. Similarly, private keys, which are more complex alphanumeric strings, also grant direct access to a user's funds. The malicious extensions are specifically designed to target these sensitive pieces of information during the initial setup or import of a wallet into the browser extension.
Trust Wallet researchers have provided specific details about the modus operandi of these extensions, noting that they are not merely phishing attempts but actively malicious software embedded within the browser extension framework. The extensions are designed to blend in with legitimate applications, making it difficult for users to distinguish them from genuine tools. Once installed, they lie dormant until a user attempts to import or set up a cryptocurrency wallet, at which point the malicious code activates. The stolen information is then sent to a command-and-control server, allowing the attackers to drain the compromised wallets. The researchers have not yet disclosed the specific names of all 16 extensions to prevent further widespread infection, but they have alerted Mozilla to take action.
This incident underscores the critical importance of vigilance when installing browser extensions, especially those that handle financial information or sensitive credentials. Users are strongly advised to download extensions only from official sources, carefully review user reviews and developer information, and be wary of extensions that request excessive permissions. The cryptocurrency space continues to be a prime target for cybercriminals, and the methods employed to compromise user accounts are becoming increasingly sophisticated. The discovery of these 16 malicious Firefox extensions serves as a stark reminder for cryptocurrency users to prioritize security best practices, including the use of hardware wallets for significant holdings and the careful vetting of all software and browser add-ons.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.