CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Crypto Draining Fake Wallet Extensions Flood Firefox Store
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Crypto Draining Fake Wallet Extensions Flood Firefox Store
News

Crypto Draining Fake Wallet Extensions Flood Firefox Store

CoinRSS
Last updated: July 5, 2025 2:41 am
CoinRSS Published July 5, 2025
Share

Contents
In briefA “cat and mouse game”Daily Debrief Newsletter

In brief

  • More than 40 malicious extensions were impersonating real crypto wallets on the Firefox Add-ons store as part of the “FoxyWallet” malware campaign.
  • Wallets impersonated by malicious extensions include Coinbase Wallet, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero, according to Koi Security.
  • Firefox creator Mozilla said it was engaged in a “constant cat and mouse game” with malware developers seeking to bypass its detection methods, in a recent blog post.

A malware campaign is leveraging malicious Firefox add-ons that impersonate legitimate crypto wallets in a bid to steal unwary users’ funds, according to a new study.

Koi Security discovered that more than 40 malicious extensions were impersonating real crypto wallets as part of the “FoxyWallet” campaign, including Coinbase Wallet, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero.

The malware campaign sees malicious code used to exfiltrate wallet secrets to attacker-controlled servers. The code checks for input strings that are longer than 30 characters to filter for realistic wallet keys/seed phrases, before sending the data to the attackers. The victim’s external IP address is also transmitted to the attacker, allowing for tracking or further targeting.

Koi Security explained that the FoxyWallet creators “took advantage of the fact that official extensions are open source,” adding that, “They cloned the real codebases and inserted their own malicious logic, creating extensions that behaved as expected while secretly stealing sensitive data.”

Further exploration of these malicious extensions suggest a Russian-speaking threat actor, with Russian-language comments found in their code, as well as in metadata found in a PDF file discovered on the command-and-control server.

The campaign appears to have been active since at least April, with new malicious extensions added last week, according to Koi Security. Some fake extensions were still available on the Firefox Add-ons store as recently as yesterday, despite the firm having reported their findings to Firefox using its official reporting tool.

Firefox creators Mozilla released a statement Thursday saying that the firm is “aware of attempts to exploit Firefox’s add-ons ecosystem using malicious crypto-stealing extensions,” adding that “Through improved tooling and process, we have taken steps to identify and take down such add-ons quickly.”

The firm added that many of the malicious extensions flagged in Koi Security’s report had been removed by its team before publication, and that it is “in the process of reviewing the remaining few add-ons they identified as part of our ongoing commitment to protecting users.”

A “cat and mouse game”

Mozilla pointed to a recent blog post reporting on its efforts to address the threat of crypto-stealing extensions, in which its Add-ons Operations Manager Andreas Wagner noted that the firm had uncovered “hundreds” of scam crypto wallets in recent years. “It’s a constant cat and mouse game,” Wagner said, as malware developers attempt to “work around our detection methods.”

Decrypt has reached out to Mozilla and will update this article should they respond.

To avoid being a victim of FoxyWallet or similar scams, it is suggested that users only download and install extensions from verified publishers, treat extensions as full software assets, use an extension allow list to restrict installation to pre-approved, validated extensions only, and implement continuous monitoring, not just one-time scanning.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

Hex Crypto Founder Richard Heart Hit With Interpol Red Notice

OpenAI Whistleblower Found Dead in San Francisco Apartment in Apparent Suicide

Bitcoin, Altcoins Plunge as Trump’s Threat to Assassinate Iran Leader Escalates Middle East Tensions

Uniswap swarmed by whales: Odds of UNI pushing to $27 now are…

Assessing if SHIB can reach $0.000017 – THIS pattern suggests…

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Chainlink – Whales are buying, but will the price react?
Next Article Bitcoin: 20K BTC moved after 14 years – Should holders be worried?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Tether’s last stand? GENIUS Act leaves USDT with 3 doors AND a ticking clock
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?