Loading market data...

and content, and generate a meta description in Norwegian.

and content, and generate a meta description in Norwegian.

Dozens of fake Firefox wallet extensions are linked to crypto-stealing malware. At least 40 of them are confirmed malicious, and they impersonate OKX, Rabby, and TronLink. The extensions harvest recovery phrases from users who type them in.

How the fake extensions work

The malicious add-ons are built to look like the real wallet interfaces. They ask the user to enter their recovery phrase, the string of words that controls the wallet. When a user types it, the phrase is captured and sent off to the attacker.

Which wallets are being impersonated

The three named targets are OKX, Rabby, and TronLink. All are widely used in the crypto ecosystem. OKX is a major exchange, Rabby is a popular DeFi wallet, and TronLink is the standard wallet for TRON-based assets. A fake version of any of these could fool users who are in a hurry.

The size of the problem

So far, 40 extensions have been confirmed as malicious. The overall count of fake add-ons is described as “dozens,” meaning there may be more that haven’t been caught yet. Users who have installed a wallet extension from an unofficial source should be especially cautious.

If you typed your recovery phrase

Anyone who entered a recovery phrase into one of these fake extensions should assume that phrase is compromised. The phrase is the only key to the wallet. Moving funds to a new wallet with a fresh phrase is the practical move, though it’s not a fun task.