16 Malicious Firefox Extensions Tried to Steal Your Crypto Wallets
16 malicious Firefox extensions have been removed from Mozilla's extension catalog. The reason: they reused Rabby Wallet's code, behaved like Rabby Wallet... but quietly sent your recovery phrase to a server controlled by hackers. Here's what we know.
On October 7, 2026, the Socket Threat Research team published a report on a campaign targeting Firefox cryptocurrency wallet users. In total, 16 extensions are affected. They pose as cryptocurrency wallets, utilities, or browser tools, but their code intercepts recovery phrases and private keys when the user imports their crypto wallet.
Socket believes this is a continuation of a previous campaign documented in August 2026, notably because it uses the same infrastructure. At that time, researchers had identified 77 related Firefox extensions, including 40 malicious ones.
Two families of clones: Rabby and OKX Wallet
The 16 extensions are split into two distinct groups, as some target Rabby Wallet while others target OKX Wallet. Here is the list provided by Socket:

- Rabby Wallet clones
Four extensions, each made up of 1,114 files, that reuse a large portion of Rabby's code. Rabby is an Ethereum wallet that claims around 900,000 users on the Chrome Web Store. The name was changed to "Raabby WaIIet": note the subtle trick, with capital "I" characters instead of "l". Inside the extension, some screens still display the real name, and links to Rabby's official pages were kept.
But in addition, malicious functions were inserted right after the import operations: they capture 12- or 24-word recovery phrases and 64-character hexadecimal private keys, while leaving the wallet working normally. Subtle.
- OKX Wallet clones
Twelve extensions presented under the name "Portal WALLET", with an interface that reuses OKX Wallet components (more than one million users on the Chrome Web Store) and links to its real help pages. They prompt the user to import a wallet using a recovery phrase, then send it to the attackers via an HTTPS POST request.
In both cases, the methodology is the same: impersonate a legitimate crypto wallet to trick users and take control of their wallet using the recovery phrase. Another common point: the stolen secrets are sent to Cloudflare Workers endpoints controlled by the hackers.

Have you installed one of these extensions? Here's what to do
Removing the extension is essential, but it is not enough. A leaked recovery phrase makes it possible to access the wallet on another device. Here are the steps recommended by Socket in its report.
- Clean up the browser: remove the extension (and remember your other devices if you use profile sync).
- Move to a new wallet: if you entered a real recovery phrase or private key, create a new wallet from a clean device, transfer your assets, and revoke the token permissions associated with the old one.
- Do not rely on the password: changing the extension password does not invalidate either the recovery phrase or the private key. Any accounts derived from an exposed phrase must be considered compromised.
This article also gives me an opportunity to highlight two recently published articles:
- Securing Chrome, Edge, and Firefox in the enterprise
- MalExt: a directory of malicious Chrome / Edge extensions
Finally, the report provides no figures on the number of victims. You can find the full list of extension IDs and indicators of compromise at the end of Socket's report.

