Over 40 Fake Crypto Wallet Extensions on Firefox, Are Your Funds at Risk?

Source Bitcoinist

A new report from cybersecurity firm Koi Security has revealed a large-scale campaign involving fake Firefox browser extensions used to steal crypto wallet credentials.

According to the research, more than 40 extensions were found impersonating popular crypto wallet tools, allowing attackers to siphon off sensitive information from unsuspecting users.

These add-ons were designed to closely mimic legitimate applications from well-known platforms like MetaMask, Coinbase, Phantom, Trust Wallet, Exodus, OKX, and others.

Inside The Fake Wallet Extensions on Firefox

The campaign, which remains active, was first detected as far back as April 2025. In their findings released Wednesday, Koi Security confirmed that the fake extensions had been uploaded to the Firefox Add-ons store as recently as last week.

Some of these extensions were still available at the time of the report, raising concerns about the continued exposure of users’ private keys and wallet data.

Once installed, the add-ons discreetly collected sensitive credentials, creating direct access points for attackers to steal users’ assets across multiple blockchain networks.

Security researchers say this operation poses a particular threat because of its longevity, stealth, and technical sophistication. The fact that new extensions are being uploaded even now suggests the campaign is not only active but persistent, evolving to avoid detection.

By mimicking widely used wallets and slipping through browser review systems, the actors behind this effort are leveraging both social engineering and technical spoofing to target crypto users.

Tactics, Attribution, and Broader Implications for Crypto Security

In an effort to establish credibility, many of the counterfeit extensions had been padded with hundreds of five-star ratings and positive reviews. These false signals of legitimacy likely helped persuade users to download the tools without suspecting foul play.

The extensions’ design, branding, and naming conventions also closely resembled those of official wallet providers, adding another layer of deception.

Koi Security researchers found several technical indicators suggesting a potential Russian-speaking group behind the campaign. Analysis of the extensions revealed Russian-language comments embedded in the code, and documents linked to the command-and-control infrastructure contained metadata in Russian.

While these clues are not definitive, they align with tactics seen in prior threat actor campaigns originating from Eastern Europe. “While not conclusive, these artifacts suggest that the campaign may originate from a Russian-speaking threat actor group,” the report noted.

The scale and persistence of the operation point to an organized effort. Koi Security emphasized that this isn’t a one-off exploit but an evolving tactic that could target other browsers and crypto platforms in the future.

The report recommends that users avoid downloading browser extensions outside of official wallet provider recommendations and double-check developer information on add-on pages. It also encourages users to inspect permissions requested by extensions and to remove any tool they did not explicitly install or no longer recognize.

The global crypto market cap valuation on TradingView

Featured image created with DALL-E, Chart from TradingView

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin Must Clear This Critical Cost Basis Level For Continued Upside, Analyst SaysIn a recent CryptoQuant Quicktake post, contributor Crazzyblockk highlighted key Bitcoin (BTC) cost basis zones that the leading cryptocurrency must clear – or avoid breaking below – to
Author  NewsBTC
4 Month 23 Day Wed
In a recent CryptoQuant Quicktake post, contributor Crazzyblockk highlighted key Bitcoin (BTC) cost basis zones that the leading cryptocurrency must clear – or avoid breaking below – to
placeholder
Ethereum Price Tests Resistance — Breakout Could Spark RallyEthereum price started a fresh increase above the $2,480 zone. ETH is now consolidating gains and might soon aim for a move above the $2,520 resistance. Ethereum started a fresh upward move above the
Author  NewsBTC
6 Month 30 Day Mon
Ethereum price started a fresh increase above the $2,480 zone. ETH is now consolidating gains and might soon aim for a move above the $2,520 resistance. Ethereum started a fresh upward move above the
placeholder
This Altcoin Looks Like PEPE Before It Exploded, Analyst SaysA cryptocurrency analyst has pointed out how Pudgy Penguins (PENGU) is starting to look similar to Pepe (PEPE) did before its explosion. Pudgy Penguins May Be Following A Similar Path As PEPE In a
Author  NewsBTC
Yesterday 02: 27
A cryptocurrency analyst has pointed out how Pudgy Penguins (PENGU) is starting to look similar to Pepe (PEPE) did before its explosion. Pudgy Penguins May Be Following A Similar Path As PEPE In a
placeholder
Analyst Says Cycle Is Not Finished Amid 2 Years Of Bitcoin Sideways MovementBitcoin (BTC) is now 195 days into its latest sideways movement, which is part of a broader two-year stretch marked by sluggish price action and short-lived rallies. According to a crypto analyst,
Author  NewsBTC
Yesterday 02: 30
Bitcoin (BTC) is now 195 days into its latest sideways movement, which is part of a broader two-year stretch marked by sluggish price action and short-lived rallies. According to a crypto analyst,
placeholder
Gold price edges up as the post-NFP USD rally falters amid US fiscal concernsGold price (XAU/USD) attracts some dip-buying during the Asian session on Friday and for now, seems to have stalled its retracement slide from a one-and-a-half-week high touched the previous day.
Author  FXStreet
4 hours ago
Gold price (XAU/USD) attracts some dip-buying during the Asian session on Friday and for now, seems to have stalled its retracement slide from a one-and-a-half-week high touched the previous day.
goTop
quote