According to Decrypt, 40alicious Firefox extensions have been confirmed. They impersonated OKX, Rabby, and TronLink wallets and collected recovery phrases from users who entered them into the extensions.

The risk stems from the fact that a recovery phrase grants access to a crypto wallet. However, the provided materials contain only metadata and a brief synopsis of the publication; therefore, details regarding the campaign, the list of extension versions, and the number of affected users remain unconfirmed.

Technical information about the malicious code, the distribution methods of the extensions, and the response from Mozilla and the named wallet providers is required to assess the scale.