Crypto news and analysis
Security · News

40 Firefox extensions confirmed malicious in wallet-theft campaign

Socket linked 77 Firefox extension identities to a campaign that impersonated OKX, Rabby and TronLink; 40 were confirmed malicious and users who entered wallet secrets should treat them as compromised.

Illustrative cybersecurity code on a monitor.
Illustrative cybersecurity imagery; it does not depict the Firefox extensions or the Socket investigation. Photo: Unsplash · Unsplash License
From our reporting

Read the earlier context

Security · 3 min readSafePal says order-data breach exposed records of 39,798 customers

The wallet maker says names, contact details and purchase information were accessed, but seed phrases, private keys, passwords and funds were not compromised.

Suggested Academy read

Build the background

Advanced · Wallets & custody · 15 min readCommon wallet scams

Recognize seed theft, fake support, malicious approvals, address poisoning, and deceptive signatures by understanding what each request can authorize.

Loading the next story…