CONTACT FOR ADS

BTCinsider – Bitcoin, Blockchain & DeFi News
  • BOOKMARKS
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
    CryptoShow More
    Bitcoin Creator Satoshi Nakamoto Is Now Richer Than Bill Gates—And Closing In on Buffett
    Bitcoin Creator Satoshi Nakamoto Is Now Richer Than Bill Gates—And Closing In on Buffett
    17.07.2025
    Man Attempts Tattoo World Record By Inking ‘Pump.fun’ on Himself 700 Times
    Man Attempts Tattoo World Record By Inking ‘Pump.fun’ on Himself 700 Times
    17.07.2025
    House Clears Key Crypto Bills for Final Vote After Record 9-Hour Standoff
    House Clears Key Crypto Bills for Final Vote After Record 9-Hour Standoff
    17.07.2025
    Whatever Happened to the Bitcoin and Ethereum Sweater Guys?
    Whatever Happened to the Bitcoin and Ethereum Sweater Guys?
    17.07.2025
    SEC Delays Decision on Bitwise Bitcoin, Ethereum ETFs' In-kind Redemptions
    SEC Delays Decision on Bitwise Bitcoin, Ethereum ETFs’ In-kind Redemptions
    17.07.2025
  • DeFi
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
    MarketShow More
    Canary Files for Staked Injective ETF as Interest in Altcoin Funds Grows
    Canary Files for Staked Injective ETF as Interest in Altcoin Funds Grows
    18.07.2025
    BlackRock Files With SEC to Include Staking in Ethereum ETF
    BlackRock Files With SEC to Include Staking in Ethereum ETF
    17.07.2025
    Recapping the latest US data: Philly Fed, retail sales and more
    Recapping the latest US data: Philly Fed, retail sales and more
    17.07.2025
    Why famed short seller Jim Chanos is warning Bitcoin treasury companies of SPAC-style risk
    Why famed short seller Jim Chanos is warning Bitcoin treasury companies of SPAC-style risk
    17.07.2025
    Bitcoin smack dab in the middle of its adoption curve: Fidelity analyst
    Bitcoin smack dab in the middle of its adoption curve: Fidelity analyst
    17.07.2025
  • News
    • Mining
    • NFT
    • Stocks
    • Web3
    • Tech
    NewsShow More
    Crypto holders beware: Physical attacks will hit new record in 2025 for one reason, warns Chainalysis
    Crypto holders beware: Physical attacks will hit new record in 2025 for one reason, warns Chainalysis
    17.07.2025
    Cybercriminals are about to steal more crypto in 2025 than ever before, says Chainalysis
    Cybercriminals are about to steal more crypto in 2025 than ever before, says Chainalysis
    17.07.2025
    Ethereum ETFs gobble up $720m investment record in ‘clear acceleration’ to outpace Bitcoin
    Ethereum ETFs gobble up $720m investment record in ‘clear acceleration’ to outpace Bitcoin
    17.07.2025
    Axie Infinity exec, NFT scammer testify in Roman Storm trial
    Axie Infinity exec, NFT scammer testify in Roman Storm trial
    17.07.2025
    Is ‘Ethereum season’ dawning following a 30% rally? The three reasons why Arthur Hayes says yes
    Is ‘Ethereum season’ dawning following a 30% rally? The three reasons why Arthur Hayes says yes
    16.07.2025
  • Contact Us
Reading: Crypto Draining Fake Wallet Extensions Flood Firefox Store
Share
  • bitcoinBitcoin(BTC)$119,949.83
  • ethereumEthereum(ETH)$3,470.14
  • rippleXRP(XRP)$3.45
  • tetherTether USDt(USDT)$1.00
  • binancecoinBNB(BNB)$719.96
  • solanaSolana(SOL)$175.00
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.213972
  • tronTRON(TRX)$0.316331
  • cardanoCardano(ADA)$0.81
Font ResizerAa
BTCinsider – Bitcoin, Blockchain & DeFi NewsBTCinsider – Bitcoin, Blockchain & DeFi News
  • Home
  • Crypto
  • Market
  • News
  • Tech
  • Contact
Search
  • Home
  • Market
    • Business
    • Investor
  • Tech
  • News
    • Web3
    • NFT
  • DeFi
  • Crypto
Have an existing account? Sign In
Follow US
© All Rights Reserved.
Crypto

Crypto Draining Fake Wallet Extensions Flood Firefox Store

Roman Hasley
Last updated: 04.07.2025 7:48 PM
Roman Hasley
Published: 04.07.2025
Share
Crypto Draining Fake Wallet Extensions Flood Firefox Store

Firefox Users Warned: Malicious Extensions Impersonate Crypto Wallets

April 24, 2024

Key Findings

  • Over 40 Firefox extensions part of the “FoxyWallet” campaign falsely mimicked popular cryptocurrency wallets.
  • Malicious extensions impersonating Coinbase Wallet, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero were identified.
  • FoyleWallets cloned legitimate wallet extension source code to embed malware, hoping to steal seed phrases or tracking IPs.
  • A threat actor using Russian appears behind the operation, based on code comments and language clues.
  • The campaign reportedly started as far back as April, with new variants appearing recently.

Analysis of the Malware Practice

According to cybersecurity researchers at Koi Security, the FoxyWallet malware leverages companion browser extensions that mimic leading crypto wallet applications. This deceptive tactic allows the extensions to behave normally, masking their illicit purpose.

Contents
Firefox Users Warned: Malicious Extensions Impersonate Crypto WalletsKey FindingsAnalysis of the Malware PracticeTimeline and PersistenceA “Cat and Mouse Game”Recommendations for UsersFurther Information

Upon installing the malicious extension, attackers secretly harvest sensitive cryptocurrency wallet keys or seed phrases. The embedded code specifically looks for strings exceeding 30 characters—a proxy for likely real seed phrases—collecting and transmitting this classified information to control servers, potentially enabling fund theft. The malware explicitly sends the user’s external IP address for tracking purposes.

Koi Security elaborated that the threat actors gained an edge by exploiting the open-source nature of official Firefox extensions. By cloning authentic code bases and inserting malicious logic, they created convincing fakes.

Timeline and Persistence

Koi Security’s investigation indicates campaign activity dating back to at least April. Recent weeks saw newly uploaded malicious extensions, with some instances remaining listed on the Firefox Add-ons website as late as April 23rd despite Koi’s red flags. Mozilla’s involvement began when these researchers reported the issue through the platform’s designated security channel.

In response, Mozilla confirmed awareness of the threat “exploiting Firefox’s add-on ecosystem” through malicious crypto-focused extensions. They emphasized their commitment to swift countermeasures, having already preempted some FoxyWallet releases and continuing to monitor the situation to “protect users.” This demonstrates an “ongoing commitment” where identified vulnerabilities are under review.

A “Cat and Mouse Game”

Mozilla’s Add-ons Operations Manager, Andreas Wagner, noted the persistent challenge in a recent blog post. During FoxyWallet’s concealment and propagation, malware developers aimed to utilize “hundreds” of scams,with many potentially lingering over years. As stated, the environment fosters a “constant cat and mouse game,” requiring constant vigilance and adaptation on Mozilla’s part to counter ever-evolving scams and bypass detection measures.

Recommendations for Users

Given the risks posed by FoxyWallet and comparable threats, user precautions are crucial:

  • Whenever possible, obtain and install software—including browser extensions—from verified, official sources.
  • Consider extensions as software assets that should meet specific security standards before deployment.
  • Employ an extension allow list to ensure that only components explicitly vetted and pre-approved by security standards can install automatically.
  • Implement continuous monitoring for known malicious entities, rather than relying on one-time periodic scans for safety.

Further Information

At the time of publication, contact has been made with Mozilla regarding these findings. Decrypt anticipates updating this report upon receiving responses.

Ethereum Co-Founder Vitalik Buterin Floats Gas Cap for ZK ‘Endgame’
Linda Yaccarino Leaves Elon Musk’s X Following Grok ‘MechaHitler’ Debacle
SEC Delays Decision on Bitwise Bitcoin, Ethereum ETFs’ In-kind Redemptions
Connecticut Flips State Bitcoin Reserve Trend, Bans All Government Crypto Investments
Man Attempts Tattoo World Record By Inking ‘Pump.fun’ on Himself 700 Times

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Telegram Email Copy Link Print
Share
Previous Article BONK Eyes Breakout as ETF Buzz and Burn Trigger Spark Fresh Rally BONK Eyes Breakout as ETF Buzz and Burn Trigger Spark Fresh Rally
Next Article You Can Buy a Martian Meteorite With Bitcoin—If You Have Upwards of $4 Million You Can Buy a Martian Meteorite With Bitcoin—If You Have Upwards of $4 Million
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Canary Files for Staked Injective ETF as Interest in Altcoin Funds Grows
Canary Files for Staked Injective ETF as Interest in Altcoin Funds Grows
'Dogecoin Millionaire' Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
‘Dogecoin Millionaire’ Is Now a Pepe Millionaire—And He’s Stacking These Meme Coins Next
Performance Art Duo Operator 'Make Movement Collectible' With NFTs
Performance Art Duo Operator ‘Make Movement Collectible’ With NFTs

You Might Also Like

Solana Treasury Firm DeFi Development Corp. Boosts Convertible Notes Offering to $112 Million
Crypto

Solana Treasury Firm DeFi Development Corp. Boosts Convertible Notes Offering to $112 Million

03.07.2025
How Far Would You Go to Pump Your Meme Coin?
Crypto

How Far Would You Go to Pump Your Meme Coin?

19.06.2025
Bitcoin Headed for 'Best Ever' Second Half of the Year: Standard Chartered
Crypto

Bitcoin Headed for ‘Best Ever’ Second Half of the Year: Standard Chartered

03.07.2025
TikTok Hits Back At Congressman's '$300 Million Bribe' Accusation Over Trump Meme Coin
Crypto

TikTok Hits Back At Congressman’s ‘$300 Million Bribe’ Accusation Over Trump Meme Coin

20.06.2025

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

BTCinsider – Bitcoin, Blockchain & DeFi News

With 20 million users, we are the #1 global business blockchain and cryptocurrency news network.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up