BTC $79,232.17 -0.52%
ETH $2,474.83 -0.95%
BNB $698.85 -1.54%
XRP $1.47 -2.98%
SOL $98.32 +1.13%
TRX $0.3414 -0.64%
DOGE $0.0891 -3.17%
ADA $0.2154 -3.54%
BCH $267.72 -3.23%
LINK $11.55 -0.95%
HYPE $81.34 +2.79%
AAVE $129.44 -5.12%
SUI $0.7881 -5.24%
XLM $0.1908 -3.34%
ZEC $807.37 -4.17%
BTC $79,232.17 -0.52%
ETH $2,474.83 -0.95%
BNB $698.85 -1.54%
XRP $1.47 -2.98%
SOL $98.32 +1.13%
TRX $0.3414 -0.64%
DOGE $0.0891 -3.17%
ADA $0.2154 -3.54%
BCH $267.72 -3.23%
LINK $11.55 -0.95%
HYPE $81.34 +2.79%
AAVE $129.44 -5.12%
SUI $0.7881 -5.24%
XLM $0.1908 -3.34%
ZEC $807.37 -4.17%

firefox

All
Article
Flash

first_img Socket exposes 77 malicious wallet extensions for Firefox, 40 confirmed to steal mnemonic phrases

According to a report by Decrypt, security company Socket released research results linking 77 Firefox extensions to what it calls a "wallet theft factory," with 40 confirmed to have malicious behavior.These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, tricking users into importing wallets through fake wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla's signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online at the time of Socket's report.About half of the extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the inputted mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content.Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran sports score applications sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released as score applications for sports like football and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the "wallet theft factory," but cautioned that it has not confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys into these extensions should consider it a "permanent leak" and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.
app_icon
ChainCatcher Building the Web3 world with innovations.