Firefox extensions removed after wallet-secret theft finding
AI-generated image

Firefox extensions removed after wallet-secret theft finding

Sixteen malicious Firefox extensions copied Rabby and OKX wallets to capture recovery phrases and private keys; affected users should replace their wallets.

Malicious Firefox extensions copied cryptocurrency wallets to capture the secrets users entered while importing their accounts, according to research by application security company Socket. The company identified 16 add-ons posing as wallet access tools, desktop utilities or browser tools. All had been removed as of October 5, 2026, but anyone who supplied genuine wallet secrets through them should treat those secrets as compromised.

Socket researcher Joseph Edwards reported that the extensions intercepted recovery phrases and private keys during wallet imports and attempted to transmit them to attacker-controlled Cloudflare Workers. A recovery phrase is a set of words that can restore access to a wallet; a private key is secret data used to authorise transactions. Cloudflare Workers is a service for running code online. In this case, attackers used it to receive stolen information, not as evidence of a vulnerability in Cloudflare itself.

Four extensions imitated Rabby Wallet and the remaining ones copied OKX Wallet. All but one were found contacting "*.icy-star-f45c.workers[.]dev", the address pattern associated with the collection infrastructure. The source describes attempts to send wallet secrets there, but does not give a victim count or a confirmed amount of cryptocurrency lost.

Socket assessed the activity as a continuation of a wave it documented in August 2026. The operators appear to have changed package names, versions, extension IDs, descriptions and visual presentation while retaining wallet interfaces, code for handling credentials and network infrastructure. Extension IDs are the identifiers browsers use to distinguish add-ons. These changes matter when checking an installation: a different name or appearance does not necessarily indicate different underlying behaviour.

The reported extension identifiers and versions are: view-focus-bright@webtools.co@6.12.2; quick-track-nest@tabtools.co@8.1.18; vibe-kit-tool@fasttools.co@9.21.9; edge-hub-snap@protools.net@4.12.24; core-hub-peak@neattools.example@8.24.21; sipoo-grozza@browserweb.com@2.1; mozart-seo@webtools.com@1.4; clean-file-bar@neattools.com@4.21.8; clean-net-timer@plugify.example@4.17.1; manager-square@webtools.com@1.4; manager-course@webtools.com@1.4; val-andrew@browserweb.com@1.4; manager-team@browserweb.com@1.4; valory-andrew@browserweb.com@1.4; franklin-uk@browserweb.com@1.4; and franklin-uro@browserweb.com@1.4.

For someone who installed one of these Firefox extensions and entered a real recovery phrase or private key, removal is not enough to make the existing wallet safe. The reported advice is to create a new wallet on a clean system and transfer assets to it. For website owners and businesses using cryptocurrency, the immediate exposure is the wallet secret submitted through the browser, rather than a reported flaw in their website or hosting software.

The Hacker News places Socket's findings alongside several other browser-extension discoveries. One Firefox add-on, "ID- Pay" (pdf-para-texto@extensao.local), presented identity verification as a prerequisite for opening protected PDF documents. It could download additional malicious code from attacker-controlled systems and insert JavaScript, code executed by browsers, into the legitimate "accounts.google[.]com" site to steal session cookies. These cookies are pieces of browser data that can keep a user signed in.

Another cluster comprised 32 extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons Store. Disguised as productivity utilities, they gathered data, tracked browsing and covertly changed the active tab to an address supplied by remotely downloaded settings. The campaign has operated since March 2025 and was attributed to a Korean-speaking threat actor. Separately, about 30 extensions posing as productivity, privacy and cryptocurrency tools used the names of legitimate, prominent financial personalities. They redirected users to fake wallet pages seeking recovery phrases, while avoiding English-speaking users and environments used to analyse suspicious software.

A further group consisted of 31 Russian-language Chrome extensions advertised as VPNs, or virtual private networks, for particular services blocked in the country. The advertised services included Anthropic Claude, Facebook, Google Gemini, LinkedIn, Netflix, Notion, OpenAI ChatGPT, Spotify, Telegram, Threads, Wikipedia, X and YouTube. After installation, the extensions routed browser traffic through a proxy, an intermediary server. They fetched the server list from a GitHub Pages address, with Blogger, Google Docs and Telegram used as backup sources.

The report also describes Stylish, a Chrome Web Store extension that intercepts conversations with ChatGPT, Gemini, Claude, Perplexity, Character.AI and GitHub Copilot and sends the full response text to its operator. Another extension, Urban VPN, reportedly transmitted visited addresses to BIScience servers through an anti-phishing feature that never produced a phishing warning. Phishing is an attempt to trick people into handing over sensitive information. Urban VPN had previously faced accusations of collecting AI chatbot conversations, although its developers said AI-related processing happened only after users explicitly enabled "AI Protection". They also fixed a high-severity vulnerability earlier in May that had let any website send arbitrary commands to the extension without checking the sending site's identity.

The Chrome Web Store extension "Pop up blocker for Chrome? - Poper Blocker" was described as an ad blocker containing an interpreter, software that reads and carries out instructions. It downloaded instructions from a command-and-control server, the system an operator uses to direct software, bypassing Google's Manifest V3 rules against that behaviour. Those instructions could collect browsing history, social media profile information, AI chatbot interactions and browser fingerprints, combinations of browser details used to distinguish users or devices.

These separate findings involve different behaviours and should not all be attributed to the operators behind the wallet copies. Their practical relevance for IT teams is the need to review browser add-ons as installed software with access to sensitive activity. The source recommends removing unneeded extensions, auditing those in managed environments and monitoring their behaviour while they run. AEU-I's security-first IT, infrastructure and consulting services are relevant to businesses seeking help with the wider IT security practices surrounding browser use.

For the wallet case, the priority remains specific: check for the identified Firefox extensions, remove them and replace any wallet whose real recovery phrase or private key was entered into a fake interface. Their removal from distribution does not undo the disclosure of a secret already supplied to an attacker.

How to Protect Yourself

  1. Open Firefox's menu, choose Add-ons and themes, then Extensions, and remove any add-on identified in this report.
  2. If you entered your wallet's recovery words or private key into one of these add-ons, create a new wallet on a clean device and transfer your assets to it.
  3. Use the wallet provider's official website to find its browser extension rather than choosing an add-on by its name or appearance alone.
  4. In your browser's extensions page, remove tools you no longer use.
  5. If an affected extension is on a work computer, tell your IT team which add-on you installed and whether you entered wallet secrets.

Terms Explained

  • recovery phrase A set of secret words that can restore access to a cryptocurrency wallet.
  • private key Secret data that allows someone to authorise transactions from a cryptocurrency wallet.
  • Cloudflare Workers A service that lets people run code online without operating their own servers.
  • session cookies Small pieces of browser data that can keep you signed in to a website.
  • proxy A server that passes internet traffic between your browser and the sites you visit.
  • phishing An attempt to trick someone into revealing sensitive information through a deceptive message or page.
  • browser fingerprints Combinations of browser and device details that can help distinguish one user from another.

Related AEU services