Socket Exposes 77 Firefox Malicious Wallet Extensions, 40 Confirmed Stealing Seed Phrases
Security firm Socket published research linking 77 Firefox extensions to a malicious campaign it calls an "offside wallet theft factory," with 40 confirmed to contain malicious behavior that…
Security firm Socket published research linking 77 Firefox extensions to a malicious campaign it calls an "offside wallet theft factory," with 40 confirmed to contain malicious behavior that steals seed phrases or private keys. The extensions impersonate Web3 products such as OKX, Rabby Wallet, and TronLink, guiding users to import wallets through fake wallet interfaces or using modified authentic wallet code to steal seed phrases and private keys during user input. Mozilla signature records show the campaign was active between March 9 and August 3, with several extensions still online at the time of Socket's report.
Roughly half of the extensions display fake wallet interfaces requiring users to import existing wallets to intercept seed phrases; 13 are modified versions of Rabby that function normally while sending wallet account data to external servers; 5 specifically collect saved credentials and clipboard content. Another 37 are disguised as password generators, dark mode, VPN, currency converter, and note-taking tools, but actually run sports score applications sharing hardcoded credentials; 9 were initially released as score apps and later updated with theft code. Socket warned it has not confirmed whether they are controlled by the same operator and advised any users who entered seed phrases or private keys into these extensions to treat them as "permanently compromised" and immediately transfer funds to new wallets.
[ChainCatcher]
Original: https://www.chaincatcher.com/article/2285393
insigtX content is informational and educational, not investment advice.