Malicious Firefox Extensions Pose as Web3 Products, Steal Wallet Secrets from Thousands of Users
A recent investigation has uncovered a sophisticated threat campaign targeting users of the popular web browser Mozilla Firefox. At least 40 malicious extensions, masquerading as legitimate Web3 products, have been found to be secretly stealing sensitive wallet secrets and other user credentials. The affected users are estimated to be in the tens of thousands.
The malicious extensions, which were available for download from the official Firefox add-ons repository, used a combination of social engineering tactics and technical trickery to gain access to sensitive user data. They claimed to offer features such as cryptocurrency tracking, wallet management, and other Web3-related services, but instead, they exploited vulnerabilities in the browser’s cross-domain policies to steal credentials from unsuspecting users.
The extensions worked by establishing a network of collaborating add-ons that could communicate with each other across different domains. This allowed them to sidestep security measures designed to prevent unauthorized data exchange between websites and Firefox extensions. The malicious code would then harvest sensitive information, including wallet secrets, API keys, and authentication tokens, which were later sent back to the attackers’ command and control servers.
The scale of the attack is staggering, with affected users spanning across multiple countries and regions. The malicious extensions were able to evade detection for several months, suggesting that their authors had a sophisticated understanding of Firefox’s security mechanisms and how to manipulate them. This highlights the importance of vigilance in the face of emerging threats, particularly those related to Web3 technologies.
The exposure of user credentials has severe consequences, as it can be used to unlock active attack paths and compromise online accounts, including social media, email, and financial services. It’s essential for users to stay informed about the risks associated with Web3 technologies and take proactive measures to protect their digital identities.
To avoid falling victim to similar attacks in the future, Firefox users are advised to regularly review their installed extensions, check their permissions, and remove any that seem suspicious or unnecessary. Additionally, users should enable two-factor authentication (2FA) whenever possible and consider using a password manager to generate unique, complex passwords for each account. By being mindful of these precautions, individuals can significantly reduce the risk of identity exposure and minimize potential damage from malicious attacks.
Source: The Hacker News — 2026-08-20