Rabby

Policy Regula
2026-08-29 01:31:09

Weekly crypto picks: Cosmos exploit hits ecosystem, YZi Labs backs 24 startups, Sun Yuchen faces civil dispute

PANews’ weekly roundup brought together a wide spread of crypto stories, from a major security failure in the Cosmos ecosystem to fresh early-stage funding and a legal dispute involving Sun Yuchen. The most consequential incident centered on the Cosmos EVM module, where a publicly disclosed high-risk patch was not communicated to downstream projects in advance. MANTRA, TAC and KiiChain were named among the affected chains, and the KII, TAC and NES tokens each fell more than 90% within hours after treasury funds were drained. The roundup also highlighted YZi Labs’ EASY Residency S4 batch, where 24 early-stage projects each received a $500,000 investment. The selected teams are focused on areas including stablecoin payments, on-chain foreign exchange and AI agents, pointing to continued attention on next-generation on-chain financial infrastructure. Elsewhere, the selection covered Bitcoin market structure, Upbit’s faster listing pace, Ethena’s token and ecosystem overhaul, Firefox wallet-themed malware, and a series of interviews with industry figures including CZ, Sun Yuchen, Shenyu and Tom Lee. In the news brief section, Sun Yuchen’s lawyer said a civil lawsuit over a property dispute had been filed against Jing and Jing’s parents, and that the case had been formally accepted.

390
Weekly crypto picks: Cosmos exploit hits ecosystem, YZi Labs backs 24 startups, Sun Yuchen faces civil dispute
Firefox exten
2026-08-27 13:40:10

At Least 40 Malicious Firefox Extensions Found Stealing Crypto Wallet Seed Phrases and Private Keys

Security researchers at Socket said attackers have published at least 40 high-risk malicious extensions in Mozilla Firefox’s official add-on store, disguising them as major Web3 wallets including OKX, Rabby Wallet, and TronLink. The campaign, which Socket said has been active since March 2026, was described as an industrialized extension-based theft operation built to harvest seed phrases and private keys and then drain user funds. According to Socket’s Aug. 20, 2026 report, the operation extends beyond those 40 wallet-themed extensions. It also links to 37 decoy add-ons posing as sports score tools and other harmless utilities, bringing the total to 77 related repositories and release branches. Some extensions reportedly began as benign-looking tools and were later converted into wallet-stealing programs while keeping the same Firefox extension ID. Socket said the attackers relied on a shared codebase for mass distribution, used a Supabase cloud project as a remote command-and-control switch to activate malicious behavior after review, and kept reserve shell extensions ready to replace any add-ons taken down. The report also warned that browser extensions can access tabs, web requests, storage, and page content, making them especially dangerous for crypto users who enter seed phrases, private keys, and passwords in the browser.

280
At Least 40 Malicious Firefox Extensions Found Stealing Crypto Wallet Seed Phrases and Private Keys
Hyperliquid
2026-08-26 08:56:04

MetaMask leads Hyperliquid Builder revenue over the past 30 days, followed by Phantom and Trust Wallet

HyperTracker data shows MetaMask ranked first in Hyperliquid Builder revenue over the past 30 days with about $1.3248 million, while Phantom placed second with roughly $1.2568 million and Trust Wallet came third at about $900,200. The top 10 list also included Invo, fomo, Rabby, Trasia, Blockchain, and two wallet addresses identified as 0xc7...b71a and 0x7c...e781, alongside their respective 30-day trading volumes. According to the data, MetaMask recorded $1.43 billion in 30-day volume, Phantom posted $2.29 billion, and Trust Wallet reached $1.5 billion. Hyperliquid’s Builder Code mechanism allows wallets, trading front ends, trading tools, or bots to attach a source identifier to orders through the on-chain Builder field and receive a share of fees from the order flow they route. The figures indicate that major wallets and trading interfaces are becoming key channels for revenue capture in the Hyperliquid ecosystem, with both MetaMask and Phantom generating more than $1.2 million in Builder revenue during the period.

180
MetaMask leads Hyperliquid Builder revenue over the past 30 days, followed by Phantom and Trust Wallet
Firefox exten
2026-08-25 14:14:33

40 fake Firefox wallet extensions identified as malicious and targeting seed phrases

Dozens of fake wallet extensions on Firefox have been identified as malicious, according to Techub News, citing Decrypt. The extensions reportedly disguised themselves as well-known wallet brands including OKX, Rabby and TronLink. Their purpose was to steal users’ recovery phrases once those seed phrases were entered. The report said 40 extensions have already been confirmed to show malicious behavior. The case adds to ongoing security risks around browser-based wallet tools, with attackers using impersonation of recognized crypto products to collect sensitive user credentials. In this instance, the reported target was mnemonic recovery data entered by users into the fake extensions.

140
40 fake Firefox wallet extensions identified as malicious and targeting seed phrases
Firefox
2026-08-25 14:17:21

Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases

Security firm Socket said it found a cluster of malicious cryptocurrency wallet extensions targeting Firefox users and tied them to an operation it calls "Offside Wallet Theft Factory." The company linked 77 extension identities to the campaign, with 40 confirmed as malicious, and said the activity ran for at least from March to August 2026. The extensions mainly impersonated well-known Web3 wallets including OKX, Rabby Wallet and TronLink, using highly convincing wallet interfaces to trick users into importing existing wallets and handing over seed phrases or private keys. Socket said roughly half of the malicious extensions directly prompted users to enter seed phrases. Another 13 were tampered Rabby builds that sent wallet account data to external servers when users saved account information, while five collected stored credentials and clipboard contents. Socket also found that at least nine of the malicious extensions had previously operated as sports score apps covering football, basketball and the NBA, building up users and reviews before later switching to wallet-stealing code through updates. It warned that anyone who entered a seed phrase or private key into the affected extensions should treat those credentials as permanently compromised and move funds to a brand-new wallet immediately.

280
Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases
Firefox exten
2026-08-25 14:18:31

Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious

Security firm Socket has linked 77 Firefox extensions to a malicious operation it calls the "Overstep wallet theft factory," according to a report cited by Decrypt. Of those, 40 have been confirmed as malicious. The extensions allegedly impersonated Web3 products including OKX, Rabby Wallet and TronLink, either by presenting fake wallet interfaces that pushed users to import existing wallets or by using modified versions of legitimate wallet code to steal seed phrases and private keys as they were entered. Mozilla signing records cited by Socket show the activity ran from March 9 to Aug. 3, and several of the extensions were still live when the report was published. Socket said about half of the extensions displayed realistic wallet interfaces designed to capture seed phrases or private keys. Another 13 were modified Rabby builds that functioned normally while sending stored account data to external servers, while five were built to collect saved credentials and clipboard contents. Socket also found 37 extensions posing as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually running a sports scores app that shared the same hardcoded credential. Nine confirmed malicious extensions were first published as football or basketball score apps before later updates swapped in wallet-stealing code. Socket said users who entered seed phrases or private keys into any of these extensions should treat them as permanently compromised and move funds to a new wallet immediately.

260
Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious
Firefox
2026-08-25 14:10:05

Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed Malicious

Socket’s threat research team said it linked 77 Firefox extension identities through shared code, infrastructure, and publishing patterns, and confirmed 40 of them as malicious. According to the company, the extensions impersonated crypto wallet and Web3 brands including OKX, Rabby Wallet, and TronLink, with many designed to trick users into importing an existing wallet and entering a recovery phrase or private key. Mozilla signing records placed the campaign between March 9 and August 3, and Socket said several of the extensions were still live when it reported them. The researchers also found that 37 other extension identities were presented as unrelated utilities but actually displayed live sports scores. In nine confirmed cases, football, basketball, NBA, or American football score apps were later updated into wallet-stealing malware, allowing the operators to retain the install base and review history built by the original apps. Socket named the pattern the “Offside Wallet Theft Factory,” while saying it has not established that every extension was run by a single operator. The firm warned that users who entered a recovery phrase or private key into any of the affected extensions should treat those credentials as permanently compromised and move funds to a new wallet.

280
Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed Malicious
fomo
2026-08-14 10:19:28

fomo co-founder Se Yong says platform has 1.3 million users and is betting on mobile social trading

fomo co-founder Se Yong said in an Aug. 12 interview that the social meme trading platform has reached about 1.3 million users and is adding roughly 30,000 new users a day. He said the company is not trying to become a traditional pro-grade meme trading terminal. Instead, it wants to simplify cross-chain trading, make trust visible through public rankings, and turn trading into a social product that can reach users beyond crypto-native circles. In the interview, Se Yong also described how he first entered crypto through trading on Avalanche in 2021, how painful cross-chain flows on Base helped shape the product idea behind fomo, and why he sees mobile trading and social trading as the two core directions for the platform. He said the team wants users to think less about whether funds sit on SOL, ETH, or BNB and more about having a single usable balance. Se Yong added that fomo recently launched Clans, a new social feature that lets users join groups, view holdings, and compete on public leaderboards. Over time, he said, the feature could expand into internal chat, recruiting, subscriptions, shared treasuries, and even public clan addresses for airdrops. On competition, he said rival products are healthy and that fomo’s goal is to grow the overall market rather than protect a narrow slice of existing crypto users.

830
fomo co-founder Se Yong says platform has 1.3 million users and is betting on mobile social trading