Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Crypto Draining Fake Wallet Extensions Flood Firefox Store

Crypto Draining Fake Wallet Extensions Flood Firefox Store

CryptoNewsNetCryptoNewsNet2025/07/04 13:55
By:decrypt.co

A malware campaign is leveraging malicious Firefox add-ons that impersonate legitimate crypto wallets in a bid to steal unwary users’ funds, according to a new study.

Koi Security discovered that more than 40 malicious extensions were impersonating real crypto wallets as part of the “FoxyWallet” campaign, including Coinbase Wallet, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero.

The malware campaign sees malicious code used to exfiltrate wallet secrets to attacker-controlled servers. The code checks for input strings that are longer than 30 characters to filter for realistic wallet keys/seed phrases, before sending the data to the attackers. The victim's external IP address is also transmitted to the attacker, allowing for tracking or further targeting.

Koi Security explained that the FoxyWallet creators “took advantage of the fact that official extensions are open source,” adding that, “They cloned the real codebases and inserted their own malicious logic, creating extensions that behaved as expected while secretly stealing sensitive data."

Further exploration of these malicious extensions suggest a Russian-speaking threat actor, with Russian-language comments found in their code, as well as in metadata found in a PDF file discovered on the command-and-control server.

The campaign appears to have been active since at least April, with new malicious extensions added last week, according to Koi Security. Some fake extensions were still available on the Firefox Add-ons store as recently as yesterday, despite the firm having reported their findings to Firefox using its official reporting tool.

Firefox creators Mozilla released a statement Thursday saying that the firm is “aware of attempts to exploit Firefox’s add-ons ecosystem using malicious crypto-stealing extensions,” adding that “Through improved tooling and process, we have taken steps to identify and take down such add-ons quickly.”

The firm added that many of the malicious extensions flagged in Koi Security’s report had been removed by its team before publication, and that it is “in the process of reviewing the remaining few add-ons they identified as part of our ongoing commitment to protecting users."

A "cat and mouse game"

Mozilla pointed to a recent blog post reporting on its efforts to address the threat of crypto-stealing extensions, in which its Add-ons Operations Manager Andreas Wagner noted that the firm had uncovered “hundreds” of scam crypto wallets in recent years. “It’s a constant cat and mouse game,” Wagner said, as malware developers attempt to “work around our detection methods.”

Decrypt has reached out to Mozilla and will update this article should they respond.

To avoid being a victim of FoxyWallet or similar scams, it is suggested that users only download and install extensions from verified publishers, treat extensions as full software assets, use an extension allow list to restrict installation to pre-approved, validated extensions only, and implement continuous monitoring, not just one-time scanning.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Investors Chase Mutuum Finance as DeFi Disruption Unfolds

- Mutuum Finance (MUTM), a DeFi project with a hybrid P2C/P2P lending model, is gaining traction as a potential bull market altcoin. - Its Stage 6 presale has raised $15M+ with 15,720+ investors, featuring a $0.035 token price set to rise 14.29% in Stage 7. - MUTM plans an Ethereum-based stablecoin with a 95.0 CertiK trust score and offers $150K in incentives for security testing and token giveaways. - Analysts highlight MUTM's sustainable tokenomics and ecosystem growth as disruptive factors in DeFi, draw

ainvest2025/08/29 10:03
Investors Chase Mutuum Finance as DeFi Disruption Unfolds

Pudgy Penguins (PENGU): Buy-the-Dip Opportunity Amid ETF Delays and Price Correction

- Pudgy Penguins (PENGU) faces short-term price declines but shows oversold technical indicators and key support levels near $0.03618. - Fundamental catalysts include utility expansion via Pudgy Party game, $13M in physical toy sales, and institutional NFT adoption by BTCS Inc. - Regulatory uncertainty from delayed Canary PENGU ETF creates asymmetric risk/reward, with potential institutional liquidity if approved by October 2025. - Contrarian investors see buy-the-dip opportunities as on-chain data shows r

ainvest2025/08/29 10:00
Pudgy Penguins (PENGU): Buy-the-Dip Opportunity Amid ETF Delays and Price Correction

MBOX -585.37% in 24 Hours Amid Volatile Market Conditions

- MBOX plummeted 585.37% in 24 hours to $0.0599, showcasing extreme volatility amid sharp 736% weekly decline. - Despite 1028.57% monthly rebound, year-to-date drop of 6963.82% highlights asset's unpredictable price swings and high-risk profile. - Technical analysis reveals breakdown below key support levels with no buying pressure, reinforcing bearish sentiment across markets. - Analysts warn next critical support below $0.05 could trigger further erosion, with momentum indicators showing deteriorating de

ainvest2025/08/29 09:48
MBOX -585.37% in 24 Hours Amid Volatile Market Conditions

Layer Brett’s Staking Rewards Outpace Meme Coin Giants

- Analysts highlight Layer Brett ($LBRETT) as a top 2025 meme coin, leveraging Ethereum Layer 2 tech for fast transactions and low fees. - Offering 55,000% APY staking rewards and a fixed 10B token supply, it outpaces FLOKI and WIF in utility and scalability. - FLOKI faces a 25% price drop, while WIF struggles with retracement, lacking Layer Brett's infrastructure and community-driven growth. - Emerging projects like DeepSnitch AI aim to blend meme culture with fraud detection tools, but Layer Brett remain

ainvest2025/08/29 09:48
Layer Brett’s Staking Rewards Outpace Meme Coin Giants