Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases
Key Takeaways A total of 16 malicious Firefox extensions impersonated legitimate cryptocurrency wallets to steal recovery phrases and private keys. The compromised extensions mimicked Rabby Wallet...
Key Takeaways
- A total of 16 malicious Firefox extensions impersonated legitimate cryptocurrency wallets to steal recovery phrases and private keys.
- The compromised extensions mimicked Rabby Wallet and OKX Wallet interfaces, tricking users into revealing sensitive information during wallet import.
- Mozilla removed the fraudulent add-ons from its marketplace by October 5, 2026, but users who have already entered credentials remain at risk.
- The stolen data was exfiltrated to attacker-controlled Cloudflare Workers via both GET and POST requests.
- Users who interacted with these extensions should immediately secure their assets and revoke token approvals.
A recent surge in malicious activity has seen cybercriminals deploy 16 counterfeit Firefox extensions designed to pilfer cryptocurrency recovery phrases and private keys from unsuspecting users. These add-ons, masquerading as legitimate wallet portals, desktop tools, and browser utilities, secretly transmitted sensitive user data to attacker-controlled Cloudflare Workers.
Table Of Content
The campaign specifically targeted users of Rabby Wallet and OKX Wallet, meticulously replicating their interfaces to transform standard wallet import processes into sophisticated traps. While Mozilla acted swiftly to remove these malicious extensions from its official marketplace by October 5, 2026, the removal does not mitigate the risk for individuals who previously entered their recovery phrases or private keys into an active fraudulent extension. Researchers from Socket.dev identified this threat and released their findings on October 7, detailing the operational tactics of the attackers.
Socket.dev’s investigation uncovered four extensive clones of Rabby Wallet and twelve smaller extensions styled after OKX Wallet. Among the smaller packages, eleven contained active background scripts engineered for credential theft, while one included similar theft code that was not executed through its standard packaging workflow. The researchers confidently linked this activity to a prior August campaign, citing shared codebases, infrastructure, and a consistent tracking marker. This continuity highlights a persistent strategy by attackers to re-deploy related malicious packages under new guises, continuously leveraging fake wallet interfaces and Cloudflare Workers for data exfiltration.
Deceptive Wallet Interfaces and Malicious Code
Each of the Rabby Wallet clones was remarkably complex, comprising 1,114 files. These files included fully functional-looking wallet import screens, account management modules, and transaction interfaces. Rather than employing rudimentary phishing pages, the attackers developed comprehensive wallet applications, integrating their theft functionalities seamlessly. To enhance credibility, some official Rabby links and DeBank service configurations were retained within the altered software.
Despite the sophisticated mimicry, inconsistencies in branding were present; for instance, the welcome screen correctly displayed “Rabby Wallet,” while other sections used a misspelled variation. Crucially, the malicious functions were strategically positioned to activate immediately following private-key and recovery-phrase import operations. These functions were designed to accept both 12-word or 24-word recovery phrases and 64-character hexadecimal private keys, capturing the exact secrets processed by the purported wallet. This method exploits user trust in familiar interfaces, rather than relying on vulnerabilities in genuine wallet services. The copied application could even continue its normal wallet operations while the theft code ran in the background, making detection difficult for the user.
The smaller extensions, which presented an OKX-derived interface under generic portal branding, also featured an import form that validated input for exactly 12 or 24 words before transmitting the phrase to a background handler. This handler was programmed to clean input by removing surrounding spaces, rejecting empty entries, and preventing the submission of duplicate phrases during a single session.
Exfiltration Via Cloudflare Workers
The Rabby Wallet clones exfiltrated stolen secrets embedded within GET request URLs, with a secondary request method available as a fallback. This method not only exposed recovery material to the attacker’s designated endpoint but also to any intermediate systems that log request URLs. In contrast, the active OKX-style handlers transmitted raw phrases securely via HTTPS POST requests containing JSON data.
One particular packaged background script offered three different transmission methods: a browser beacon, a POST request, and an image-based GET fallback. Although its internal comments falsely claimed that only a hash and word count were sent from the device, Socket.dev’s analysis confirmed that the full phrase was transmitted, with the hash serving merely to prevent duplicate submissions. A “broken” extension within the campaign lacked the necessary manifest entry to load its background script, and its interface sent messages that the handler was not configured to accept, limiting its operational capacity despite clear malicious intent. This echoes similar TronLink wallet impersonation attacks, which also leveraged copied wallet interfaces as credential traps, though with distinct delivery and collection mechanisms.
All identified extensions falsely declared that they collected no user data, directly contradicting their embedded secret-handling code. The Rabby clones further requested extensive browser access. However, Socket.dev’s static analysis did not conclusively identify a broader form-grabbing capability, confirming the primary objective as wallet-secret theft rather than comprehensive browsing data collection.
It is important to note that legitimate Rabby and DeBank domains found within the packages are not indicators of compromise themselves. Any individual who entered a legitimate recovery phrase or private key into a functional variant of these malicious extensions should consider their wallet irrevocably compromised. Socket.dev advises immediate action: remove the compromised extensions, establish a new wallet on a clean device, transfer all assets, and revoke any relevant token approvals. Simply changing the extension password will not invalidate a previously stolen recovery phrase or private key.
Defenders should meticulously audit their extension inventories, browser profiles, synchronized add-ons, and network logs against the provided indicators of compromise. Searches should prioritize matching destination hosts, request patterns, hashes, and campaign markers, ensuring that stolen phrases are redacted from alerts or case notes. Suspicious packages should be preserved for further investigation but must never be executed on an analyst’s primary workstation.
Indicators of Compromise (IoCs):-
Network and Code Indicators
| Type | Indicator | Purpose |
|---|---|---|
| Network endpoint | hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/ |
Rabby-clone secret collection |
| Network endpoint | hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/ |
OKX-style secret collection |
| Network endpoint | hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/ |
OKX-style secret collection |
| Network endpoint | hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/ |
Endpoint packaged in the broken variant |
| Campaign marker | EQOx7EIPZSNi |
Shared campaign token |
| Fake branding | Raabby WaIIet |
Rabby-clone detection string |
| Runtime message | SEED_PHRASE_IMPORT |
Recovery-phrase submission |
| Runtime message | WALLET_SYNC |
Legacy message handled by theft code |
Shared File Hashes
| File or Component | SHA-256 |
|---|---|
Rabby-clone background.js |
7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799 |
OKX core background.js |
da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd |
Broken variant background.js |
be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897 |
OKX Web3 Portal background.js |
c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f |
| Shared compact frontend | eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf |
Extension IDs and Package Hashes
| Firefox Extension ID | Version | XPI SHA-256 |
|---|---|---|
[email protected] |
6.12.2 | 2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51 |
[email protected] |
8.1.18 | 225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b |
[email protected] |
9.21.9 | 6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8 |
[email protected] |
4.12.24 | 8906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7 |
[email protected] |
8.24.21 | 9fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b |
[email protected] |
2.1 | 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35 |
[email protected] |
1.4 | 635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083 |
[email protected] |
4.21.8 | d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1 |
[email protected] |
4.17.1 | 458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7 |
[email protected] |
1.4 | bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d |
[email protected] |
1.4 | 71ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4 |
[email protected] |
1.4 | e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096 |
[email protected] |
1.4 | faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3 |
[email protected] |
1.4 | b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980 |
[email protected] |
1.4 | 4512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a |
[email protected] |
1.4 | e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Immediately Remove Malicious Extensions: If you suspect you have installed any of the identified malicious Firefox extensions, remove them from your browser without delay.
- Transfer Assets to a New Wallet: Create a brand new cryptocurrency wallet on a secure, clean device that has not been exposed to these extensions. Transfer all your digital assets from the potentially compromised wallet to this new, secure wallet.
- Revoke Token Approvals: Review and revoke any token approvals granted by the compromised wallet. This prevents attackers from executing unauthorized transactions even if they gain access to your wallet’s signing capabilities.
- Do Not Reuse Credentials: Never reuse recovery phrases or private keys that may have been exposed. Changing an extension password will not protect you if the underlying recovery phrase or private key has been stolen.
- Implement Strong Security Practices: Use hardware wallets for storing significant cryptocurrency holdings, enable two-factor authentication (2FA) wherever possible, and be extremely cautious when installing browser extensions, especially those related to financial services.
- Verify Extension Authenticity: Always verify the authenticity of any browser extension, particularly crypto wallets, by cross-referencing with the official project website. Look for direct links from the official site to the browser’s extension marketplace.
- Monitor Network Activity: Defenders should monitor network traffic for connections to the identified Cloudflare Worker endpoints and other indicators of compromise to detect and block malicious activity.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.