16 Fake Firefox Wallet Extensions Caught Stealing Crypto Recovery Phrases
Security researchers at Socket Threat Research have identified a cluster of 16 malicious Mozilla Firefox extensions that impersonate the Rabby Wallet and OKX Wallet cryptocurrency apps to harvest recovery phrases and private keys. According to an analysis published by Socket researcher Joseph Edwards, the extensions "masquerade as wallet portals, desktop utilities, and browser tools," but their underlying code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers infrastructure. Mozilla had unpublished all 16 extensions by October 5, 2026, but the takedown does nothing to protect wallets whose secrets were already exposed before removal.
Details
| Attribute | Value |
|---|---|
| Malicious extensions identified | 16 |
| Rabby Wallet clones | 4 |
| OKX Wallet clones | 12 |
| Platform | Mozilla Firefox (Manifest V2) |
| Primary exfiltration infrastructure | *.icy-star-f45c.workers.dev (Cloudflare Workers) |
| Removal date | October 5, 2026 (by Mozilla) |
| Discovered/reported by | Socket Threat Research (Joseph Edwards) |
| Legitimate Rabby Wallet install base | ~900,000 Chrome Web Store users; 500,000 Google Play downloads |
| Legitimate OKX Wallet install base | 1,000,000+ Chrome Web Store users |
| Related prior activity | Campaign Socket documented in August 2026 |
How It Worked
Impersonating Rabby Wallet
Four of the extensions were built directly from genuine Rabby Wallet source code — substantially repackaged applications containing roughly 1,114 files, including the real wallet-import screens, transaction interfaces, and key-management logic. The threat actors only partially rebranded the result: some screens displayed the deliberately misspelled name "Raabby WaIIet," while other interface elements still showed Rabby's genuine branding, an inconsistency that researchers flagged as a tell for anyone inspecting the extension closely. Example identifiers cited by Socket include view-focus-bright@webtools.co (v6.12.2), quick-track-nest@tabtools.co (v8.1.18), vibe-kit-tool@fasttools.co (v9.21.9), and edge-hub-snap@protools.net (v4.12.24).
Impersonating OKX Wallet
The remaining twelve extensions used an interface modeled on OKX Wallet, built on Firefox's Manifest V2 format with broad permissions including persistent background scripts. The extensions shared a common index.html titled "Portal WALLET," and their React-based frontend presented a recovery-phrase import workflow that validated input as exactly 12 or 24 words before passing it along — mimicking the legitimate wallet's onboarding flow closely enough to avoid raising suspicion. Example identifiers include sipoo-grozza@browserweb.com and mozart-seo@webtools.com.
Credential Interception and Exfiltration
Across both families, attackers inserted credential-stealing hooks into the background scripts and wallet-interface code. These hooks captured 12- or 24-word mnemonic recovery phrases and 64-character hexadecimal private keys at the moment of wallet import or keyring creation — while allowing the legitimate-looking wallet workflow to continue uninterrupted, so victims saw no obvious failure or error. The captured secrets were placed directly into URL query parameters and sent via outbound requests to Cloudflare Workers subdomains under icy-star-f45c.workers.dev; Socket noted that 15 of the 16 extensions contacted this shared infrastructure. Because the secrets were transmitted as URL parameters rather than in a request body, Socket warned the approach could also leak them into ordinary infrastructure and proxy logs that record request URLs. Despite exfiltrating wallet secrets, the extensions' store listings declared "none" for data collection permissions.
A Continuation of Earlier Activity
Socket assesses this cluster as a continuation of a campaign first documented in August 2026, with the same threat actors rotating package names, version numbers, extension IDs, descriptions, and presentation layers between waves — while reusing the same underlying wallet interfaces, credential-handling logic, and exfiltration infrastructure. The reuse of distinctive code paths and the shared Cloudflare Workers domain allowed researchers to tie the new batch back to the earlier operation.
Impact Assessment
| Impact Area | Description |
|---|---|
| Direct financial loss | Any recovery phrase or private key entered into a fake import screen is permanently compromised, regardless of removal |
| Scale of exposure | Extensions cloned apps with a combined install base exceeding 2 million users across legitimate storefronts, giving the lookalikes broad credibility |
| Detection difficulty | Reused genuine wallet code and functioning import flows meant victims experienced no visible errors during theft |
| Remediation complexity | Changing an extension password or uninstalling the add-on does not revoke an already-exposed seed phrase or private key |
| Secondary exposure risk | URL-parameter exfiltration may have also leaked secrets into third-party infrastructure and proxy logs beyond the attackers' own systems |
| Ecosystem trust | Repeated waves of wallet-impersonating extensions erode confidence in official add-on store review processes |
Recommendations
For Affected Users
Anyone who installed one of the identified extensions and entered a recovery phrase or private key into its import screen should treat that wallet as fully compromised, regardless of whether a transaction error appeared. Create a new wallet from a clean, trusted device using a freshly generated recovery phrase, then migrate all assets immediately. Revoke any token approvals or smart-contract allowances tied to the exposed wallet address, since an attacker holding the seed phrase can drain funds at any time — not just at the moment of theft.
For All Firefox Extension Users
Install cryptocurrency wallet extensions only by searching the official project's own website for a verified link to the Firefox Add-ons store, rather than searching the store directly, where lookalikes can rank alongside or above the genuine listing. Before importing a recovery phrase into any extension, verify the publisher, review count, and extension ID against the wallet vendor's official documentation. Treat a "declares no data collection" badge as informational only — it is a self-reported claim, not a technical guarantee.
For Security Teams and IT Administrators
Add icy-star-f45c.workers.dev and its observed subdomains to outbound network blocklists, and audit browser-extension inventories (via endpoint management or MDM policy) for the extension IDs associated with this and the related August 2026 campaign. Consider enforcing an allowlist for browser extensions on corporate or BYOD endpoints that handle organizational crypto treasury or custody operations, and flag any extension requesting webRequest or persistent background-script permissions alongside wallet-import functionality for manual review.
Key Takeaways
- Socket Threat Research identified 16 malicious Firefox extensions — 4 cloning Rabby Wallet and 12 cloning OKX Wallet — built largely from genuine wallet source code.
- The malware hooked import and keyring-creation functions to capture 12/24-word recovery phrases and 64-character private keys while letting the normal wallet flow continue.
- Stolen secrets were exfiltrated as URL query parameters to Cloudflare Workers infrastructure under
icy-star-f45c.workers.dev, shared by 15 of the 16 extensions. - Mozilla removed all 16 extensions by October 5, 2026, but removal does not undo exposure for anyone who already entered a recovery phrase or private key.
- Socket ties the cluster to an earlier campaign it documented in August 2026, with the same actors rotating extension names, IDs, and versions while reusing core infrastructure.
- Affected users must assume compromise, migrate to a freshly generated wallet on a clean device, and revoke token approvals — changing only the extension password is not sufficient.