Threat Intelligence

Fake Rabby and OKX Wallet Extensions on Firefox Caught Stealing Crypto Recovery Phrases

The Hacker News · 8 Oct 2026
Key Takeaway Regularly audit the browser extensions on staff devices, remove any that are unneeded or unfamiliar, and never enter a wallet recovery phrase into an extension you cannot verify as genuine.

Security firm Socket has uncovered a cluster of 16 malicious Mozilla Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys. The add-ons posed as wallet portals, desktop utilities and browser tools. Four are clones of Rabby Wallet, and the rest are clones of OKX Wallet.

According to researcher Joseph Edwards, the extensions' code intercepts secrets when a user imports a wallet, then attempts to send them to attacker-controlled Cloudflare Workers. All but one of the extensions contacted the same domain. The activity is assessed to continue an earlier wave documented in August 2026. The attackers appear to be rotating package names, versions, extension IDs, descriptions and visual presentation, while reusing the same wallet interfaces, credential-handling logic and network infrastructure.

As of October 5, 2026, all the extensions have been removed. Anyone who entered a real recovery phrase or private key into one of these fake wallets should assume compromise, create a new wallet from a clean system and move their assets. The findings coincide with other malicious or suspicious extensions found for Firefox, Chrome and Edge in recent months. Users are advised to review installed extensions and remove those they no longer need, while organisations should audit extensions in managed environments and use behaviour-based monitoring to spot suspicious activity.

malicious extensions Firefox cryptocurrency browser security

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.