
Mozilla removed 16 malicious Firefox extensions that impersonated cryptocurrency wallets to steal recovery phrases and private keys and send them to attacker-controlled servers.
Socket Threat Research identified four extensions built from Rabby Wallet’s code and twelve others using an interface modeled on OKX Wallet. According to Socket, Mozilla had unpublished all sixteen extensions by October 5, 2026.
However, this action does not remediate the situation for users who installed the extensions, and they need to take immediate steps to protect their assets.
The researchers linked the operation with high confidence to a crypto-theft campaign they investigated in August, citing shared infrastructure, credential-stealing techniques, and a campaign identifier embedded across the packages.
Rabby and OKX are established cryptocurrency wallets used to manage digital assets and interact with decentralized applications. The legitimate Chrome extensions have approximately 900,000 and more than one million users, respectively.
Cloned wallets hide credential theft
The four Rabby clones were substantially repackaged applications, each containing 1,114 files, including wallet import screens, transaction interfaces, and key-management code.
They partially changed their branding to “Raabby WaIIet,” while other screens still displayed Rabby’s genuine name. The packages also retained links to official Rabby applications, legal pages, and services, helping the imitation appear familiar.

Socket
Attackers inserted credential-stealing functions into both the background code and wallet interface. These hooks captured 12- or 24-word recovery phrases and 64-character hexadecimal private keys during import and keyring creation, while letting the underlying wallet workflow continue.
The stolen material was placed directly into URL query parameters and sent to a Cloudflare Workers endpoint. Socket notes that this approach could also expose secrets through infrastructure logs that record request URLs.
The twelve smaller extensions presented a “Portal WALLET” interface with OKX-like branding, retained OKX interface components, and linked to genuine OKX help and terms pages.
Their shared frontend prompted users to import a wallet using a 12- or 24-word recovery phrase. Active background variants processed the phrase and attempted to transmit it, generally through an HTTPS POST request.

Socket
One background variant included multiple delivery methods: a browser beacon, a fetch request, and an image request as a fallback. Although its comments claimed that only a hash and word count left the device, Socket found that the payload contained the complete recovery phrase.
One extension was broken, but still malicious
One package, sipoo-grozza@browserweb.com, could not execute its theft routine through the normal installation flow. Its manifest failed to load the background script, and its frontend and background code used incompatible message types.
Socket characterized this as a packaging defect, pointing to explicit credential-collection and transmission code still present in the extension.
All sixteen manifests declared that the extensions collected no data, contradicting their credential-handling code. The report does not provide victim totals or confirmed cryptocurrency losses.
Users who installed any listed extension should remove it and check other Firefox devices and synchronized profiles. Anyone who entered a genuine recovery phrase or private key into a functioning variant should create a new wallet from a clean device, transfer their assets, and revoke approvals associated with the exposed wallet.
Changing the extension password does not invalidate a stolen recovery phrase or private key. Every account derived from an exposed phrase should be treated as compromised.







Leave a Reply