Crypto news report · source clearly identified
Fake Firefox Wallet Extensions Harvest Users’ Recovery Phrases
Security researchers identified dozens of malicious Firefox extensions that mimic popular crypto wallets such as OKX, Rabby and TronLink, stealing recovery phrases from unsuspecting users.

Security analysts have uncovered a wave of counterfeit browser extensions for Firefox that masquerade as legitimate cryptocurrency wallets. The extensions are designed to trick users into entering their recovery phrases, allowing attackers to gain full control of the associated accounts.
Scope of the Threat
Forty extensions have been confirmed as malicious. Each one imitates the look and branding of well‑known wallet applications, making detection difficult for average users.
Impersonated Wallets
- OKX – a major exchange offering a browser‑based wallet.
- Rabby – a popular wallet interface for interacting with decentralized applications.
- TronLink – the official wallet for the Tron blockchain.
How the Malware Operates
The fake extensions prompt users to input their recovery (seed) phrases, often under the pretense of “account recovery” or “security verification.” Once entered, the phrase is transmitted to the attackers, who can then reconstruct the wallet and transfer assets.
Recommendations for Users
- Only install wallet extensions from official sources or the official Firefox Add‑ons store.
- Verify the publisher’s identity and check user reviews before installation.
- Never share recovery phrases with any extension or website.
- Consider using hardware wallets for high‑value holdings.
Broader Implications
This campaign highlights the ongoing risk of social‑engineering attacks targeting crypto users via browser extensions. Vigilance and strict adherence to security best practices remain essential to protect digital assets.
Source & attribution
News Source
- Publisher
- Decrypt
- Original date
- August 25, 2026, 2:10 PM
- Original headline
- Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware