"Wallet Killers" in Your Browser: 40 Malicious Firefox Extensions Stealing Your Private Keys
Author: Zero Time Technology
Introduction {#cke_bm_1886S}
Opening your browser, entering your wallet password, pasting your mnemonic phrase, clicking "Unlock"—this is the daily routine for countless Web3 users. But have you ever thought: the browser extensions you installed might be quietly recording every character you type in the background?
On August 20, 2026, the security research team Socket released a shocking investigation report: a hacker group has listed at least 40 high-risk malicious extensions in the official Mozilla Firefox extension store, disguising them as mainstream Web3 wallets like OKX, Rabby Wallet, and TronLink, luring users to input their mnemonic phrases and private keys, and then silently robbing their assets in the background. These 40 malicious extensions are just the tip of the iceberg; the entire attack operation is also linked to another 37 shell plugins disguised as "sports event score checkers," covering a total of 77 interconnected code repositories and release branches.
Even more disturbing is that this attack has been active since March 2026 and is still ongoing. The 40 malicious extensions are lurking in countless users' browsers, and those private keys and mnemonic phrases have long fallen into the hands of the attackers.
Part 01 - The Industrialized Espionage Assembly Line of 40 Malicious Extensions
In summary: This is no longer traditional "phishing"; it is a highly industrialized, assembly line-like malicious extension supply chain.
Image source: https://socket.dev/blog/firefox-crypto-wallet-theft
Socket has named this attack "Offside Wallet Theft Factory". The attack chain is clear and efficient: attackers batch build or modify extensions and list them in the Firefox official store; once users install them, the extensions capture mnemonic phrases and private keys by remotely loading phishing pages or using built-in espionage code, completing wallet takeover and asset theft. Some extensions initially appeared as "sports score tools" and were later transformed into wallet theft programs while retaining the same Firefox extension ID. The above image visualizes this attack process.
Attackers employed three core tactics to construct this large-scale espionage operation:
1. Code Sharing + Batch Distribution (Assembly Line Production)
The 40 malicious plugins share a core espionage template, meaning attackers only need to maintain one set of malicious code to generate dozens of different "brands" of malicious extensions. Different extension names, different icons, different disguise pages—but the core logic for stealing private keys remains the same.
2. Cloud "Backdoor" Remote Control Switch (Bypassing Review)
This is the most cunning part of the attack. Attackers use a legitimate Supabase cloud database project as a remote C2 (command and control) switch. The extensions are completely "silent" when listed in the Firefox official store—no malicious code—thus passing the official review smoothly. Once approved and installed by users, attackers remotely activate the malicious logic to start stealing the mnemonic phrases and private keys entered by users.
3. 37 "Sports Tools" Shells as Support Matrix
In addition to the 40 directly stealing malicious extensions, attackers also prepared 37 shells disguised as harmless functions like sports event score checkers, VPNs, and screenshot tools. These shell extensions are not directly used for espionage but serve as reserve backdoors and release matrices—once a malicious extension is taken down, the corresponding shell extension is immediately activated to ensure the continuity of the attack.
Socket researcher Kirill Boychenko's technical analysis reveals the functional distribution of the 40 malicious extensions:
Part 02 - Why Have Browser Extensions Become the Hotspot for "Wallet Killers"?
In summary: Browser extensions have extremely high permissions, which users often overlook when installing them.
Browser extensions are designed with extremely high contextual permissions—covering tabs (reading all open tabs), webRequest (intercepting and modifying network requests), storage (reading and writing local storage data), and full site DOM read/write permissions.
For cryptocurrency wallet users, the browser is the primary entry point for fund interactions. You enter your mnemonic phrase, connect your wallet, sign transactions—all sensitive operations are completed in the browser. A malicious extension can easily:
• Read what you input on any webpage: including mnemonic phrases, private keys, passwords.
• Intercept and modify webpage content: overlaying a fake login box on the real wallet page.
• Read and modify the clipboard: quietly replacing the wallet address you copied with the hacker's address.
• Send network requests: transmitting the stolen data back to the attacker's server in real-time.
Once an extension is swapped or poisoned, any multi-factor authentication (MFA) becomes meaningless. Because the malicious extension bypasses not your account password, but directly reads your private key itself.
Part 03 - How to Identify Malicious Extensions? Four-Step Self-Check Method
In summary: Don't wait until your assets are stolen to regret it; check your browser extensions now.
✅Step 1: Open the Extension Management Page
In Firefox, type about:addons in the address bar and press Enter to view the list of all installed extensions.
✅Step 2: Check Suspicious Extensions One by One
Focus on the following points:
• Extensions installed from unofficial channels: If you did not install directly from the wallet's official website, disable it immediately.
• Extensions with unusual names: Attackers use homoglyphs to disguise themselves as legitimate wallet names, such as replacing English letters with Cyrillic letters, which are hard to distinguish by the naked eye.
• Extensions with unrelated functions: Why would a "sports score checker" tool need to read your browser data?
• Extensions with excessive permissions: A simple tool extension requesting permissions like tabs, webRequest, storage, etc., is a high-risk signal.
Confirmed malicious extensions include: "Safe-Themes", "Rabbit For Desktop", "Rabb-Walӏet CryptoPortfolio", etc.
✅Step 3: Immediately Uninstall and Rotate Credentials
If you find suspicious extensions, disable and uninstall them immediately. If you have entered mnemonic phrases or private keys in affected environments, you should transfer your crypto assets to a new address on a clean device.
✅Step 4: Check Clipboard History
Some malicious extensions may hijack the clipboard, replacing the wallet address you copied. Before making large transfers, be sure to repeatedly verify every character of the recipient address—not just the first and last few characters, but all of them.
Part 04 - How to Avoid Becoming the Next Victim?
In summary: Cut off the source rather than remedying it afterwards.
1. Recognize the Official Only Download Channel
Absolutely do not install extensions through search engine ads or third-party redirect links. Always navigate from the wallet's official website homepage to the extension store or search directly in the store for versions published by the official developer account.
2. Prefer Hardware Cold Wallets
For large amounts of crypto assets, prioritize using offline hardware cold wallets like Ledger or Trezor for physically isolated signing. The private keys of hardware wallets never leave the device itself, so even if the browser is fully controlled by malicious extensions, attackers cannot directly access your private keys.
3. Regularly Audit Extension Permissions
Even trusted extensions are worth regularly checking for permission changes. Extensions may add malicious features during updates, and users often overlook update logs. Regularly open about:addons to take a quick look; it takes only a few minutes but could help you avoid losses of hundreds of thousands.
4. Don't Trust the Illusion of "Safety"
Many people believe that "Firefox official store review = safe"—but the 40 malicious extensions this time precisely illustrate that the official store's review can be bypassed. Passing the review only means that no malicious code was found at the time of listing, not that it will never become malicious.
Conclusion
40 malicious Firefox extensions, 77 associated repositories, continuously active since March 2026—this is not an accidental phishing attack, but a highly industrialized malicious extension supply chain.
The permission design of browser extensions gives them extremely high access capabilities, while users' blind trust in the "official store" gives attackers an opportunity. The lesson from this attack is clear: official store ≠ safe, passing review ≠ always safe.
As an ordinary user, there is not much you can do, but it is effective enough: do not install unnecessary extensions, only install from official channels, use hardware wallets for large assets, and regularly check the installed list.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Nvidia Earnings Beat and Gold Price Outlook: How Jackson Hole Could Move NVDA and Gold

The SEC Sends Its Overhaul of Crypto Custody Rules to the White House Without Revealing the Content

JAN3 CEO advocates for 'Bitcoin Signing Device' terminology

Global Debt Cycle May Enter 'Debt Cancellation' Phase

The Digitalization of Real Estate Ownership: What Happens to Your Rights, Risks, and Liquidity?

July PCE and Bitcoin: Why Inflation Didn't Derail the Rally

Intel Prepares BFF Driver to Combat Stuck Bits in Aging Processors

Nvidia May Swing $280 Billion After Earnings: What's at Stake

Deflation in the IPCA-15 for August: What Changes for Interest Rates and Investments

TMX Airdrop Guide: Deposit, Trade and Earn Rewards on WEEX

WEEX Telegram Mini App Launch: Get Up to $1,500 in BTC Rewards + Win an iPhone 17 Pro

Bitcoin Spot Demand: The Signal That Hadn't Reappeared Since the October 2025 Record

Vietcombank Warns of AI-Driven Fraud

Operation Lighthouse: 14,000 Leads Delivered to Investigators Against Child Exploitation Networks

What is the cost of cheap borrowing?

Ledger Wallet Vulnerability; Users Must Update Ethereum App to Version 1.22.2

The Best AI Models for Trading: A Comparison of the Top 10 Models

A $215 billion altcoin rally rests on Bitcoin holding its reclaimed market structure

AI is in a Credit Expansion Phase: The Stronger AI Becomes, the More the Federal Reserve Needs to Cut Rates

EIP-8363 Quantitative Review: What Does Ethereum Want to Regain by Cutting Staking 'Subsidies'?

AI Agent's 'Coming of Age': What Step Is Missing from Simulation Training to Real Trading?

Mining Artificial Intelligence: Why Bitcoin Miners Are Changing Their Business Model

CFTC Considers the Viability of Perpetual Futures in GPU Computing

When Computing Power Becomes a Trading Asset - From Computing Power Futures to Computing Power Dollars

Security Experiment for ML-DSA Institutional Transfers Begins on NEAR Testnet

EY Han Young and Upstage Sign Agreement to Support Sovereign AI Adoption

NoOnes crypto platform enters withdrawal-only mode, users urged to withdraw funds

Four years ago, a cryptocurrency mogul disappeared; now his successor has vanished

Will Crypto-Trump Cause a Pump?








