COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Uncovering the Dangers of Fake Crypto Wallet Extensions in Mozilla’s Firefox Store
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency Security > Uncovering the Dangers of Fake Crypto Wallet Extensions in Mozilla’s Firefox Store
Cryptocurrency Security

Uncovering the Dangers of Fake Crypto Wallet Extensions in Mozilla’s Firefox Store

In Brief

  • Over 40 fake wallet extensions found in Firefox store, risking user assets.

  • Extensions mimic legitimate wallets, collecting sensitive information via scripts.

  • Russian-speaking threat actors suspected, with ongoing uploads dodging detections.

İlayda Peker
İlayda Peker 10 months ago
Share
SHARE

In a concerning discovery, over forty counterfeit extensions mimicking popular wallet applications like Coinbase, MetaMask, and Trust Wallet remain active on Mozilla’s Firefox extension store. According to Koi Security’s report dated July 2, 2025, these fake extensions jeopardize user assets by clandestinely collecting cryptocurrency wallet credentials. Researchers confirmed the persistence of this deceptive campaign since at least April, with new extensions added to the store as recently as last week. Hundreds of fake five-star reviews deceptively boost the extensions’ credibility.

Contents
Counterfeit Extensions Attack Firefox StoreRussian Clues Unmask Attackers

Counterfeit Extensions Attack Firefox Store

The fake extensions mimic the official logos and descriptions of leading cryptocurrency wallet services like MetaMask, presenting an air of legitimacy. By using popular keywords in store search results, they rapidly climb the download charts. Once installed, although the browser interface appears genuine, embedded scripts capture private keys and recovery phrases, sending them to malicious servers.

Koi Security noted that the malicious code is hidden within closed-source JavaScript modules, evading automated scans. By abusing Firefox’s permission management, the extensions demand extensive web-tracking rights and can capture user passwords entered in new tabs. Unwitting victims install what they believe is a single wallet extension, but actually become targets for multiple scripts.

Russian Clues Unmask Attackers

The report highlights discoveries of Russian comments in PDF files and source code notes hosted on the command-and-control servers linked to the malicious extensions. Although security researchers imply these clues suggest a Russian-speaking threat actor, they acknowledge the lack of definitive proof. However, geographic timestamps, file paths, and error messages reinforcing the same language bolster the findings.

Most importantly, since the initial attack in April, more than 60 versions have been uploaded, with the latest malicious deployment occurring just a week ago. These extensions continuously update and, when detection signatures emerge, change names to reappear under the radar. Koi Security advises that some copies remain unchecked in the Firefox store and urges users to upgrade extensions only through links redirected from official sites.

You can follow our news on Telegram, Facebook & Coinmarketcap & X
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

French police charge 88 in $41M crypto kidnapping wave

Aave commits $58 million in ETH to DeFi United aid fund

DeFi attack wipes $292 million as $10B exits Aave

Arbitrum freezes over 30,000 ETH after KelpDAO exploit

JPMorgan warns $20B wiped from DeFi, investors shift to USDT

İlayda Peker 3 July, 2025 - 2:37 pm 3 July, 2025 - 2:37 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
Uluslararası İlişkiler ve Siyaset Bilimi Mezunu, Kitap sever.
Previous Article Solana ETF Achieves Milestone on Opening Day
Next Article IMF Rejects Pakistan’s Bold Energy Subsidy Plan for Crypto Mining
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Trump raises EU auto tariffs to 25 percent
Bitcoin (BTC) Economy
Bitcoin nears 80,000 dollars after 3 percent surge
Bitcoin (BTC) Cryptocurrency News
ChangeNOW launches “Beyond the Hype” for 8 million users
Hyperliquid (HYPE)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?