Millions of Firefox users are in the dark about a sinister threat lurking in their browsers. At least 40 malicious extensions, masquerading as legitimate Web3 products, have been discovered to be stealing wallet secrets and sensitive information from unsuspecting users. The alarming discovery highlights the importance of verifying the authenticity of browser add-ons, particularly those claiming to offer cutting-edge technologies like cryptocurrency management.
The malicious extensions, which were available for download on the Firefox Add-on store, used a combination of social engineering tactics and technical exploits to compromise user security. By posing as reputable Web3 products, these extensions gained users’ trust, only to subsequently pilfer their wallet secrets, login credentials, and other sensitive data. The attackers relied on the victims’ own browser settings, leveraging cross-domain privilege escalation techniques to bypass security measures and access restricted information.
The malicious extensions worked by exploiting a fundamental weakness in the way modern web applications handle user permissions and data sharing between domains. By manipulating the browser’s permission system, these extensions were able to gain elevated privileges, allowing them to access sensitive information stored within users’ browsers. This approach is particularly effective due to the widespread adoption of cross-origin resource sharing (CORS) across web applications.
The affected users are likely those who have installed Web3-related extensions on their Firefox browsers in an effort to manage cryptocurrency wallets or engage with decentralized finance services. The malicious extensions were cleverly designed to mimic legitimate products, making it difficult for even tech-savvy individuals to distinguish between the two. As a result, millions of users may be at risk of having their sensitive information compromised.
The discovery of these malicious extensions serves as a stark reminder of the ongoing cat-and-mouse game between cybersecurity professionals and attackers. It highlights the need for browser developers and extension creators to prioritize security and implement robust verification mechanisms to prevent such threats from arising in the future. In the meantime, users must remain vigilant when installing new extensions, ensuring that they only download add-ons from trusted sources.
To avoid falling victim to similar attacks, Firefox users should exercise extreme caution when installing Web3-related extensions. Verify the extension’s authenticity by checking its source code on platforms like GitHub and reviewing user reviews. Be wary of extensions that seem too good (or convenient) to be true, as they may be hiding malicious intentions beneath a veneer of legitimacy.
Source: The Hacker News — 2026-08-20