16 Firefox Extensions Impersonate Wallets to Steal Seeds
Socket found 16 malicious Firefox extensions that copied Rabby and OKX wallet screens and stole recovery phrases and private keys during import flows. The campaign was built to look like ordinary wallet setup, not an obvious pop-up, and Mozilla has since unpublished the extensions.
The trick is simple: when a user imports a seed phrase or private key, the fake extension captures that secret and sends it out through Cloudflare Workers in the background. Several clones reuse the same lure, package patterns, and network path, so trusting the apparent publisher name or removing one add-on does not break the family.
For anyone allowing Firefox extensions on managed machines, the exposure sits at wallet-import time: the extension itself can be the thief, and once a real recovery phrase is entered, the wallet is effectively compromised outside the browser profile.