Fake Firefox crypto-wallet extensions linked to theft

Security researchers linked dozens of fraudulent Firefox wallet extensions to malware that harvested private keys and enabled theft; Mozilla removed the add-ons.

Security researchers reported that in recent weeks they identified dozens of fraudulent Firefox extensions that impersonated cryptocurrency wallets and were linked to malware designed to steal funds. Mozilla removed the flagged add-ons from the Firefox Add‑ons site after the reports.

The malicious extensions used names, icons and descriptions similar to legitimate wallet software to trick users into installing them. Once installed, the add‑ons executed obfuscated JavaScript and requested broad browser permissions that allowed them to read and modify web pages, intercept wallet interactions and exfiltrate sensitive data such as seed phrases, private keys and signed transaction details to attacker servers.

Analysis of the code showed content scripts that injected into decentralized application pages, logic that monitored clipboard activity for copied addresses, and remote command‑and‑control callbacks to upload harvested data. Some extensions included update mechanisms that fetched additional payloads after installation, enabling delivery of a full crypto‑stealer component once permissions were granted. The extensions requested elevated privileges including modifying pages in all tabs, reading and writing storage, and interacting with native messaging hosts.

Researchers said the campaign used typosquatting and brand impersonation to pass initial listings. Fraudulent developer profiles and forged reviews were also observed to increase apparent legitimacy. Security teams reported that affected users experienced unauthorized outgoing transactions from wallets associated with the impostor extensions.

Mozilla removed the identified add‑ons and opened investigations into how they bypassed store vetting. Security teams advised users who installed suspicious wallet extensions to remove them using the browser’s add‑ons manager, check wallets for unauthorized transactions, and move remaining funds to a new wallet whose seed phrase was never exposed to the compromised environment. Teams also recommended revoking extension permissions where possible and using hardware wallets or other cold storage for larger holdings.

Past incidents have shown browser extension ecosystems are frequently targeted because extensions can request powerful permissions and run code inside users’ browsers. Security teams continue to monitor the Firefox Add‑ons catalog and urged users to verify extension publishers and download links from official wallet sites and to inspect requested permissions before installing.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author