MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Over 40 Fake Crypto Wallet Extensions on Firefox, Are Your Funds at Risk?
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$71,332.006.82%
  • ethereumEthereum(ETH)$2,071.365.76%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$651.064.17%
  • rippleXRP(XRP)$1.414.21%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$90.247.10%
  • tronTRON(TRX)$0.2835340.86%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.25%
  • dogecoinDogecoin(DOGE)$0.0927443.30%
Blockchain

Over 40 Fake Crypto Wallet Extensions on Firefox, Are Your Funds at Risk?

Last updated: July 4, 2025 10:59 am
Published: 8 months ago
Share

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

A new report from cybersecurity firm Koi Security has revealed a large-scale campaign involving fake Firefox browser extensions used to steal crypto wallet credentials.

According to the research, more than 40 extensions were found impersonating popular crypto wallet tools, allowing attackers to siphon off sensitive information from unsuspecting users.

These add-ons were designed to closely mimic legitimate applications from well-known platforms like MetaMask, Coinbase, Phantom, Trust Wallet, Exodus, OKX, and others.

The campaign, which remains active, was first detected as far back as April 2025. In their findings released Wednesday, Koi Security confirmed that the fake extensions had been uploaded to the Firefox Add-ons store as recently as last week.

Some of these extensions were still available at the time of the report, raising concerns about the continued exposure of users’ private keys and wallet data.

Once installed, the add-ons discreetly collected sensitive credentials, creating direct access points for attackers to steal users’ assets across multiple blockchain networks.

Security researchers say this operation poses a particular threat because of its longevity, stealth, and technical sophistication. The fact that new extensions are being uploaded even now suggests the campaign is not only active but persistent, evolving to avoid detection.

By mimicking widely used wallets and slipping through browser review systems, the actors behind this effort are leveraging both social engineering and technical spoofing to target crypto users.

In an effort to establish credibility, many of the counterfeit extensions had been padded with hundreds of five-star ratings and positive reviews. These false signals of legitimacy likely helped persuade users to download the tools without suspecting foul play.

The extensions’ design, branding, and naming conventions also closely resembled those of official wallet providers, adding another layer of deception.

Koi Security researchers found several technical indicators suggesting a potential Russian-speaking group behind the campaign. Analysis of the extensions revealed Russian-language comments embedded in the code, and documents linked to the command-and-control infrastructure contained metadata in Russian.

While these clues are not definitive, they align with tactics seen in prior threat actor campaigns originating from Eastern Europe. “While not conclusive, these artifacts suggest that the campaign may originate from a Russian-speaking threat actor group,” the report noted.

The scale and persistence of the operation point to an organized effort. Koi Security emphasized that this isn’t a one-off exploit but an evolving tactic that could target other browsers and crypto platforms in the future.

The report recommends that users avoid downloading browser extensions outside of official wallet provider recommendations and double-check developer information on add-on pages. It also encourages users to inspect permissions requested by extensions and to remove any tool they did not explicitly install or no longer recognize.

Featured image created with DALL-E, Chart from TradingView

Read more on Bitcoinist.com

This news is powered by Bitcoinist.com Bitcoinist.com

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Hong Kong Stablecoin Company RedotPay Targets $4B Valuation in Planned U.S. IPO
Empery Digital Announces Update on Share Repurchase Program
Top 5 Solana (SOL) and XRP Alternatives to Add to Your August Portfolio – Including Ozak AI in Presale
Advanced X account takeover attack now targeting the crypto community
DigiFT, Chainlink, and UBS Collaborate to Automate Tokenized Fund Operations in Hong Kong

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Looking for the Next Crypto Buy? Why Pepeto Could Outshine SHIB, and PEPE
Next Article ISDA And Ant International Lead New Industry Report On Use Of Tokenized Ban…
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d