40 fake Firefox wallet extensions identified as malicious and targeting seed phrases

40 fake Firefox wallet extensions identified as malicious and targeting seed phrases

N
News Editor
2026-08-25 14:14:33
Dozens of fake wallet extensions on Firefox have been identified as malicious, according to Techub News, citing Decrypt. The extensions reportedly disguised themselves as well-known wallet brands including OKX, Rabby and TronLink. Their purpose was to steal users’ recovery phrases once those seed phrases were entered. The report said 40 extensions have already been confirmed to show malicious behavior. The case adds to ongoing security risks around browser-based wallet tools, with attackers using impersonation of recognized crypto products to collect sensitive user credentials. In this instance, the reported target was mnemonic recovery data entered by users into the fake extensions.

Dozens of fake Firefox wallet extensions have been identified as malicious, according to Techub News, citing Decrypt.

The extensions were disguised as well-known wallet brands including OKX, Rabby and TronLink. Their goal was to steal users’ recovery phrases after seed phrases were entered.

So far, 40 extensions have been confirmed to exhibit malicious behavior.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.