Fake Firefox extensions aim to steal cryptocurrency wallets

- Over 40 fake extensions compromise cryptocurrency wallets
- Criminals use wallet names like MetaMask and Coinbase
- Attacks remain active and threaten Firefox users
Cybersecurity experts have identified more than 40 malicious extensions in the Firefox browser designed to steal cryptocurrency wallet credentials. According to a report released by Koi Security, the criminals behind the operation use the names of popular platforms, such as Coinbase, MetaMask and Trust Wallet, to deceive users and collect sensitive information.
🚨 Watch out, crypto enthusiasts! Over 40 fake Firefox extensions mimicking popular wallets have been found. These phishing scams are after your private keys! Check your extensions and stay safe. 🔐 #CryptoSecurity #PhishingAlert
— ₿itBlitz (@BitBlitz) July 3, 2025
These fake extensions pose as legitimate digital wallet tools and, once installed, secretly extract sensitive data from users, exposing digital assets to theft risks. In addition to the aforementioned, other affected brands include Phantom, Exodus, OKX, MyMonero, Bitget, Leap and Keplr.
According to report , the campaign has been active since at least April 2025, with new malicious extensions being uploaded to the Firefox Add-ons Store as recently as last week. The continued activity suggests a persistent operation, with the ability to adapt and update.
To increase the credibility of the fake extensions, the attackers used fake reviews with five-star ratings. Many of the extensions had hundreds of reviews simulating positive experiences, which increased the likelihood of being installed by unsuspecting users.
Koi Security also found clues that indicate the possible involvement of a Russian-speaking cybercriminal group. Fragments of code with comments written in Russian and metadata extracted from files hosted on the servers used in the operation reinforce this suspicion. “While not conclusive, these artifacts suggest that the campaign may have originated from a Russian-speaking cybercriminal group,” the report states.
The security firm emphasizes that the campaign is ongoing, with active extensions still available in the official store. Cryptocurrency wallet users should be extra careful when installing any add-on in Firefox, checking official sources and the authenticity of the tool.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
OneFootball In-depth Analysis: Turning "Watching Football" into "Owning and Co-creating"
Football starts with the community, and OneFootball will ensure that early supporters are rewarded, rather than marginalized, in the process of co-building the club.

XRP News Today: Ripple's RLUSD Targets Africa's Financial Gaps with $700M Stablecoin Push
- Ripple launches $700M RLUSD stablecoin in Africa via Trident Digital, aiming to enhance digital payments and financial inclusion through regulatory compliance and USD-backed liquidity. - Trident commits $500M to XRP treasury, aligning with Ripple’s ecosystem to strengthen DeFi integration and blockchain innovation via staking mechanisms in African markets. - RLUSD targets cross-border payment gaps with low-cost, real-time settlements, leveraging Ripple’s CBDC experience and global regulatory partnerships

Bitcoin News Today: Regulators Power $4.2T US Crypto Surge as ETFs Ignite Mainstream Buy-In
- The US leads global crypto adoption with $4.2T in fiat-to-crypto onramps, four times higher than any other nation. - Bitcoin dominates inflows at $4.6T, while spot ETFs attracted $54.5B since 2024, driving institutional and retail participation. - APAC saw 69% annual on-chain growth led by India, while Eastern Europe tops per-capita adoption due to economic instability. - Divergent global regulations emerge, with the US GENIUS Act and EU MiCA reflecting contrasting approaches to crypto oversight.

XRP News Today: BlockDAG’s Hybrid Model Could Disrupt 2025’s Crypto Power Rankings
- BlockDAG's $389M presale and 3M users via X1 miner app highlight its rapid adoption in crypto. - Hybrid DAG-PoW model with EVM compatibility aims to solve scalability issues, attracting 300+ dApp developers. - $0.03 presale price targets $0.05 listing, competing with XRP and Cardano in 2025's institutional adoption race. - Physical miners (X10/X30/X100) and mobile mining blend retail/institutional participation, boosting network decentralization.

Trending news
MoreCrypto prices
More








