Malicious Firefox add-ons stole crypto wallet secrets, some disguised as sports tools
Firefox extensions targeted crypto wallets with hidden malware
A security company called Socket discovered 40 harmful Firefox browser extensions that stole information from crypto wallets. Nine of these extensions started as tools for checking sports scores before being changed to target crypto users.
If a user entered their wallet recovery phrase, private key, or other secret details into one of these extensions, their crypto funds could be stolen. Simply removing the extension does not fix the problem because the secrets are already exposed.
Key details about the malicious extensions
- 40 Firefox extensions were confirmed to be harmful, while 37 others were suspicious but not proven to steal data.
- Nine extensions began as sports-score tools before being repurposed to target crypto wallets.
- The campaign ran from March to August 2026, with most activity in April and late July.
- Mozilla removed at least one live phishing extension after being alerted by Socket.
How the extensions stole crypto secrets
The harmful extensions used different methods to steal crypto:
- Seven were remote-controlled phishing tools that tricked users into entering sensitive information.
- Fifteen captured recovery phrases, private keys, or other wallet secrets directly.
- Thirteen were fake versions of the Rabby wallet that sent wallet keyrings to attackers before encryption could protect them.
- Five collected login details and clipboard data, which could include copied crypto addresses.
A recovery phrase is a set of words that can restore access to a crypto wallet. A private key is a secret code that proves ownership of crypto funds. A keyring stores multiple wallet keys in one file.
What affected users should do
If a user entered their recovery phrase, private key, or used a fake Rabby wallet extension, they must create a new wallet and move their funds immediately. The old wallet is no longer safe.
Users who only had their login details or clipboard data stolen should change their passwords and check that any copied crypto addresses are correct before sending funds.
Mozilla advises users to only install extensions from the official website of the wallet provider.
What is still unknown
- It is not known how many people were affected or how much crypto was stolen.
- No confirmed victims, transactions, or total losses have been identified.
Why this matters for crypto users
This incident shows how attackers can disguise harmful software as harmless tools. Even trusted browser extensions can become dangerous if they are updated with malicious code. Users must be careful when installing any software that interacts with their crypto wallets.