Fake Firefox extensions aim to steal cryptocurrency wallets
Bitget2025/07/03 18:50- Over 40 fake extensions compromise cryptocurrency wallets
- Criminals use wallet names like MetaMask and Coinbase
- Attacks remain active and threaten Firefox users
Cybersecurity experts have identified more than 40 malicious extensions in the Firefox browser designed to steal cryptocurrency wallet credentials. According to a report released by Koi Security, the criminals behind the operation use the names of popular platforms, such as Coinbase, MetaMask and Trust Wallet, to deceive users and collect sensitive information.
🚨 Watch out, crypto enthusiasts! Over 40 fake Firefox extensions mimicking popular wallets have been found. These phishing scams are after your private keys! Check your extensions and stay safe. 🔐 #CryptoSecurity #PhishingAlert
— ₿itBlitz (@BitBlitz) July 3, 2025
These fake extensions pose as legitimate digital wallet tools and, once installed, secretly extract sensitive data from users, exposing digital assets to theft risks. In addition to the aforementioned, other affected brands include Phantom, Exodus, OKX, MyMonero, Bitget, Leap and Keplr.
According to report , the campaign has been active since at least April 2025, with new malicious extensions being uploaded to the Firefox Add-ons Store as recently as last week. The continued activity suggests a persistent operation, with the ability to adapt and update.
To increase the credibility of the fake extensions, the attackers used fake reviews with five-star ratings. Many of the extensions had hundreds of reviews simulating positive experiences, which increased the likelihood of being installed by unsuspecting users.
Koi Security also found clues that indicate the possible involvement of a Russian-speaking cybercriminal group. Fragments of code with comments written in Russian and metadata extracted from files hosted on the servers used in the operation reinforce this suspicion. “While not conclusive, these artifacts suggest that the campaign may have originated from a Russian-speaking cybercriminal group,” the report states.
The security firm emphasizes that the campaign is ongoing, with active extensions still available in the official store. Cryptocurrency wallet users should be extra careful when installing any add-on in Firefox, checking official sources and the authenticity of the tool.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
This Week's Preview: BTC Falls Below 94,000, AI "Judgment Day" and Macro "Settlement Day" Both Looming
Bitcoin and Ethereum prices have declined as the market adopts a risk-off approach ahead of the upcoming Nvidia earnings report and the release of the Federal Reserve minutes. Nvidia's earnings will influence the AI narrative and capital flows, while the Fed minutes may reinforce a hawkish stance. Summary generated by Mars AI. The accuracy and completeness of this summary are still being iteratively improved by the Mars AI model.

The Ali Qianwen app's initial launch faces a surge in traffic; the official response is "operating well, feel free to ask."
The public beta of the Qianwen app has been launched, with Alibaba introducing its personal AI assistant to the consumer market. The first day’s traffic exceeded expectations, and some users experienced service congestion. “Alibaba Qianwen crashed” quickly trended on social media, but the official response stated that the system is operating normally.

Another giant exits! The "Godfather of Silicon Valley Venture Capital" sells all Nvidia shares and buys Apple and Microsoft
Billionaire investor Peter Thiel has revealed that he has fully exited Nvidia, coinciding with rare simultaneous retreats by SoftBank and "Big Short" investor Michael Burry, further intensifying market concerns about an AI bubble.
How to evaluate whether an airdrop is worth participating in from six key dimensions?
Airdrop evaluation is both an "art and a science": it requires understanding human incentives and crypto narratives (art), as well as analyzing data and tokenomics (science).
