Researchers reported a set of 16 malicious Firefox extensions impersonating popular cryptocurrency wallets — Rabby and OKX — in order to steal wallet recovery phrases from users who install them believing them to be genuine. The pattern is the browser-extension supply-chain risk in its purest form: the extensions present as a wallet's companion software, capture the seed phrase at the point the user enters it, and can then drain the wallet without defeating any cryptography. Recovery phrases are the one credential that cannot be rotated after theft, which makes wallet-impersonation extensions disproportionately damaging relative to their modest install counts, and the impersonated brands are chosen precisely because their users hold valuable assets. Users of wallet-related browser extensions should verify publisher identity and extension signatures rather than trusting name and icon.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-10-09 |
| Source | The Hacker News |
| Reliability | Tier 2 |