Firefox users hit by malicious wallet extension attacks

来源 Cryptopolitan

Researchers from the Koi security company discovered an ongoing campaign spreading malicious wallet extensions on Firefox. The malicious apps spoof the most widely used wallets, stealing private phrases and leaving users vulnerable to being drained.

An ongoing campaign is spreading malicious extensions, spoofing some of the most common crypto wallets on Firefox. Koi security discovered some of the apps were removed, while others were still active, posing as legitimate wallets. 

The SlowMist attack team also warned users to be vigilant, as the attack is still active. The fake apps are spreading through the official Firefox app store, making them potentially more misleading and dangerous.

The attack is relatively simple, but targets the easiest type of user, who seek casual access to crypto. Using a compromised app, or inputting private phrases into one may lead to significant losses. Users are already reporting losses from the fake apps. 

Hacks and exploits accelerated in the first half of 2025, as crypto increased in value. Threats also came from DPRK hackers infiltrating projects, with hundreds potentially affected by malicious code. 

Firefox fake extensions target the most widely used wallets

Koi intercepted fake apps for some of the most widely used wallet extensions, including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox. 

The researchers discovered over 40 apps posing as wallets, with new ones appearing. Some of the fake wallets are still active on unofficial links. According to researchers, the fake apps started spreading around April 2025. 

The extensions extract and send out wallet extensions, reaching a server controlled by the attacker. The apps also transmit the user’s IP address for tracking and further targeting. 

Attackers cloned the open-source code of legitimate wallets

The attack was relatively simple, often using the legitimate wallet code for open-source projects like MetaMask. The fake apps then injected the malicious code to allow the wallet to steal data and credentials. 

The fake wallet apps were active on app stores, using the same logos and style as the original wallet. Previously, faked wallets have targeted specific niche projects, but this time, the attacker spoofed multi-asset wallets, widely used for DeFi, trading, NFT and other on-chain tasks. 

Code analysis concluded the attack most likely originated from Russia, as Russian-language code comments were discovered in some of the apps. Metadata from a file on one of the command-and-control servers also points to a Russian attacker.

Koi advices users to install an allow list filter and avoid downloading apps without vetting. Some of the apps may not show problems, but later update and change their behavior. Security researchers also advice against searching apps directly, as the results may point to fake wallets with deliberately inflated five-star reviews. The best approach is to use the wallet’s official web page or social media. 

Users were also advised to be skeptical when seeing an app with too many five-star reviews, that were artificially placed to make the app seem established and legitimate. 

KEY Difference Wire: the secret tool crypto projects use to get guaranteed media coverage

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
2025年美元年中收官:贬值10%创1970年代以来最差H1,下半年继续跌?TradingKey - 随着特朗普高关税政策的影响从提高通胀演变为美国例外论消退和美国资产大撤离,叠加美联储独立性受到质疑和降息预期升温,2025年上半年美元指数意外暴跌超10%,与华尔街2024年底的美元走势预期相去甚远。美元指数(DXY)今年已连续6个月单月下跌,从年初的110左右一度跌破97。截至6月30日,美元指数报97.09,处于近三年低位,上半年以来下跌约11%。【2025年美元指数
作者  TradingKey
6 月 30 日 周一
TradingKey - 随着特朗普高关税政策的影响从提高通胀演变为美国例外论消退和美国资产大撤离,叠加美联储独立性受到质疑和降息预期升温,2025年上半年美元指数意外暴跌超10%,与华尔街2024年底的美元走势预期相去甚远。美元指数(DXY)今年已连续6个月单月下跌,从年初的110左右一度跌破97。截至6月30日,美元指数报97.09,处于近三年低位,上半年以来下跌约11%。【2025年美元指数
placeholder
逢七必涨!美股会打破“7月上涨魔咒”吗? 7月是美股表现最强的月份之一,标普500平均回报率为3.35%。
作者  Alison Ho
7 月 01 日 周二
7月是美股表现最强的月份之一,标普500平均回报率为3.35%。
placeholder
特朗普“大而美”法案助力黄金上涨!汇丰:2025年下半年金价或承压市场对美国财政状况感到担忧,进而推动黄金价格上涨。7月1日金价一度涨至3358美元/盎司,截至7月2日发稿有所回落,报3334美元/盎司。
作者  Alison Ho
昨日 03: 32
市场对美国财政状况感到担忧,进而推动黄金价格上涨。7月1日金价一度涨至3358美元/盎司,截至7月2日发稿有所回落,报3334美元/盎司。
placeholder
美国6月非农前瞻:失业率4.3%为7月降息铺路,美股美债继续涨?TradingKey - 2025年7月3日周四,美国劳工统计局将发布6月非农就业报告,这份就业报告因美国独立纪念日假期提前一日发布。分析认为,特朗普关税的负面影响将在6月劳动力市场数据体现,美联储7月降息概率有望增加,利好美股美债等资产表现。据Factset数据,经济学家预计美国6月非农就业新增人数将从5月的13.9万人降至11.5万;失业率将反弹至4.3%,此前已连续三个月稳定在4.2%的水平
作者  TradingKey
昨日 08: 37
TradingKey - 2025年7月3日周四,美国劳工统计局将发布6月非农就业报告,这份就业报告因美国独立纪念日假期提前一日发布。分析认为,特朗普关税的负面影响将在6月劳动力市场数据体现,美联储7月降息概率有望增加,利好美股美债等资产表现。据Factset数据,经济学家预计美国6月非农就业新增人数将从5月的13.9万人降至11.5万;失业率将反弹至4.3%,此前已连续三个月稳定在4.2%的水平
placeholder
【今日市场前瞻】重磅非农来袭!比特币突破11万美元!比特币突破11万美元! 2025下半年继续涨?重磅非农来袭,市场将迎巨震;特朗普法案迎投票表决>>
作者  Alison Ho
4 小时前
比特币突破11万美元! 2025下半年继续涨?重磅非农来袭,市场将迎巨震;特朗普法案迎投票表决>>
goTop
quote