40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

August 20, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Web3 and cryptocurrency wallet users
Incident: Deployment of 40 malicious Firefox extensions designed to steal cryptocurrency wallet secrets.
Impact: Theft of private keys and recovery phrases leading to total loss of cryptocurrency funds.
Attacker: Unidentified threat actors
Analysis: Threat actors are employing a ‘bait-and-switch’ tactic, initially publishing benign sports-themed extensions before updating them with wallet-stealing payloads. The campaign leverages cloud infrastructure like Cloudflare Workers and Supabase to exfiltrate private keys and recovery phrases. This scalable approach allows attackers to rotate identities quickly to evade detection on the official marketplace.
Recommendations: Audit installed browser extensions and remove any untrusted or unnecessary add-ons.; Avoid installing Web3 wallets via browser extension stores; download directly from official developer sites.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *