Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases
Sixteen malicious Firefox extensions impersonated crypto wallets and stole recovery phrases via Cloudflare Workers.
Socket.dev identified 16 malicious Firefox extensions, four large Rabby Wallet clones and 12 smaller OKX-style add-ons, that captured 12- or 24-word recovery phrases and private keys. Mozilla had removed them from its marketplace by October 5, 2026, but phrases already submitted remain compromised. Rabby clones sent secrets in GET request URLs to Cloudflare Workers, while OKX-style handlers used HTTPS POST. Socket linked the activity to an August campaign through shared code, infrastructure, and the marker EQOx7EIPZSNi.