
What happened
Malicious add-ons mimicked three crypto wallets and harvested recovery phrases entered by users.
Why it matters
A recovery phrase is critically sensitive data, and a fake extension can hide the collection of this information behind a familiar wallet name.
According to Decrypt, 40alicious Firefox extensions have been confirmed. They impersonated OKX, Rabby, and TronLink wallets and collected recovery phrases from users who entered them into the extensions.
The risk stems from the fact that a recovery phrase grants access to a crypto wallet. However, the provided materials contain only metadata and a brief synopsis of the publication; therefore, details regarding the campaign, the list of extension versions, and the number of affected users remain unconfirmed.
Technical information about the malicious code, the distribution methods of the extensions, and the response from Mozilla and the named wallet providers is required to assess the scale.
Confirmed facts
- Decrypt reported 40 confirmed malicious Firefox extensions.
- The extensions impersonated OKX, Rabby, and TronLink.
- The extensions collected recovery phrases from users who entered them.
Context
The only source in the package is Decrypt; only its metadata synopsis is provided, not the full text or primary technical research.
What remains unknown
- Who discovered the extensions and by what method was their malicious nature confirmed?
- Are these extensions currently available to users, and have they been removed?
- How many users installed them or entered recovery phrases?
- Which extension versions and distribution channels are affected?
- Have Mozilla, OKX, Rabby, or TronLink responded to the incident?
Editorial context
Confidence: medium
If Decrypt's description is corroborated by technical data, the next practical signal will be the publication of a list of extensions, their removal from the catalog, or warnings from Mozilla and the named wallets. Significant uncertainty remains: the package lacks primary research and data on victims.