Firefox users hit by malicious wallet extension attacks

來源 Cryptopolitan

Researchers from the Koi security company discovered an ongoing campaign spreading malicious wallet extensions on Firefox. The malicious apps spoof the most widely used wallets, stealing private phrases and leaving users vulnerable to being drained.

An ongoing campaign is spreading malicious extensions, spoofing some of the most common crypto wallets on Firefox. Koi security discovered some of the apps were removed, while others were still active, posing as legitimate wallets. 

The SlowMist attack team also warned users to be vigilant, as the attack is still active. The fake apps are spreading through the official Firefox app store, making them potentially more misleading and dangerous.

The attack is relatively simple, but targets the easiest type of user, who seek casual access to crypto. Using a compromised app, or inputting private phrases into one may lead to significant losses. Users are already reporting losses from the fake apps. 

Hacks and exploits accelerated in the first half of 2025, as crypto increased in value. Threats also came from DPRK hackers infiltrating projects, with hundreds potentially affected by malicious code. 

Firefox fake extensions target the most widely used wallets

Koi intercepted fake apps for some of the most widely used wallet extensions, including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox. 

The researchers discovered over 40 apps posing as wallets, with new ones appearing. Some of the fake wallets are still active on unofficial links. According to researchers, the fake apps started spreading around April 2025. 

The extensions extract and send out wallet extensions, reaching a server controlled by the attacker. The apps also transmit the user’s IP address for tracking and further targeting. 

Attackers cloned the open-source code of legitimate wallets

The attack was relatively simple, often using the legitimate wallet code for open-source projects like MetaMask. The fake apps then injected the malicious code to allow the wallet to steal data and credentials. 

The fake wallet apps were active on app stores, using the same logos and style as the original wallet. Previously, faked wallets have targeted specific niche projects, but this time, the attacker spoofed multi-asset wallets, widely used for DeFi, trading, NFT and other on-chain tasks. 

Code analysis concluded the attack most likely originated from Russia, as Russian-language code comments were discovered in some of the apps. Metadata from a file on one of the command-and-control servers also points to a Russian attacker.

Koi advices users to install an allow list filter and avoid downloading apps without vetting. Some of the apps may not show problems, but later update and change their behavior. Security researchers also advice against searching apps directly, as the results may point to fake wallets with deliberately inflated five-star reviews. The best approach is to use the wallet’s official web page or social media. 

Users were also advised to be skeptical when seeing an app with too many five-star reviews, that were artificially placed to make the app seem established and legitimate. 

KEY Difference Wire: the secret tool crypto projects use to get guaranteed media coverage

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
AI再掀高潮!Meta股價狂飆,緊隨輝達創下歷史新高TradingKey - Meta宣佈重組AI部門,提振其股價盤中跳漲,創下新的記錄。當地時間週一(6月30日),Meta (META)股價盤中跳漲至747.9美元,創下歷史新高。截止收盤,該股收漲0.61%,報738.09美元。(哪些機構持有Meta股票,可查看「明星投資者」)【Meta股價走勢圖,來源:TradingView】Meta股價上漲主要是受該公司的人工智慧業務推動。Meta Plat
作者  TradingKey
7 月 01 日 週二
TradingKey - Meta宣佈重組AI部門,提振其股價盤中跳漲,創下新的記錄。當地時間週一(6月30日),Meta (META)股價盤中跳漲至747.9美元,創下歷史新高。截止收盤,該股收漲0.61%,報738.09美元。(哪些機構持有Meta股票,可查看「明星投資者」)【Meta股價走勢圖,來源:TradingView】Meta股價上漲主要是受該公司的人工智慧業務推動。Meta Plat
placeholder
日幣2025年上半年漲9%!7月繼續升值?分析師這樣說2025年上半年,美元/日圓(USD/JPY)累計下跌9%,創下近年來最佳表現。
作者  Alison Ho
7 月 01 日 週二
2025年上半年,美元/日圓(USD/JPY)累計下跌9%,創下近年來最佳表現。
placeholder
7月3日財經早餐:美越達成貿易協議!標普、納指收盤再創新高、WTI原油、比特幣大漲超3%在7月9日貿易談判限期逼近之際,川普宣佈美國與越南達成貿易協議。與此同時,美國6月ADP私人企業職位減少3.3萬個,遠不及預期增加9.8萬個,聯准會提前至7月降息預期升溫。另一方面,市場關注美國《大而美法案》在眾議院審議的消息,加之英國國債遭遇2022年10月10日以來最大單日拋售,潛在風險不容忽視。
作者  Insights
13 小時前
在7月9日貿易談判限期逼近之際,川普宣佈美國與越南達成貿易協議。與此同時,美國6月ADP私人企業職位減少3.3萬個,遠不及預期增加9.8萬個,聯准會提前至7月降息預期升溫。另一方面,市場關注美國《大而美法案》在眾議院審議的消息,加之英國國債遭遇2022年10月10日以來最大單日拋售,潛在風險不容忽視。
placeholder
由於美國就業數據疲軟和美聯儲降息預期,美元指數跌至97.00以下美國美元指數(DXY),即衡量美元(USD)相對於一籃子六種世界貨幣的價值指數,在週四亞洲早盤維持在96.70附近的防守態勢
作者  FXStreet
12 小時前
美國美元指數(DXY),即衡量美元(USD)相對於一籃子六種世界貨幣的價值指數,在週四亞洲早盤維持在96.70附近的防守態勢
placeholder
6月非農料失色,美債多頭大狂歡?川普法案在眾議院還有最後一關TradingKey - 美國6月「小非農」ADP就業數據不增反降凸顯美國就業市場放緩現狀,美國國債多頭交易員等待今晚可能會弱於預期的非農就業報告,以尋找支撐聯準會7月降息的可能。不過,可能引發財政擔憂的川普減稅法案在眾議院投票結果可能會影響這一前景。7月2日,美國6月ADP就業人數意外下降3.3萬,為2023年3月以來的首次負增長,遠不及預期的9.5萬,且彭博調查的經濟學家無一人預計為負值。【A
作者  TradingKey
4 小時前
TradingKey - 美國6月「小非農」ADP就業數據不增反降凸顯美國就業市場放緩現狀,美國國債多頭交易員等待今晚可能會弱於預期的非農就業報告,以尋找支撐聯準會7月降息的可能。不過,可能引發財政擔憂的川普減稅法案在眾議院投票結果可能會影響這一前景。7月2日,美國6月ADP就業人數意外下降3.3萬,為2023年3月以來的首次負增長,遠不及預期的9.5萬,且彭博調查的經濟學家無一人預計為負值。【A
goTop
quote