According to the
Socket security firm, a batch of malicious encrypted wallet extensions targeted Firefox browser users.
Currently, 77 extension identities have been linked, with 40 confirmed to be malicious, and this is expected to have started from at least March 2026. These extensions primarily impersonate well-known Web3 wallets such as OKX, Rabby Wallet, and TronLink, using highly realistic wallet interfaces to trick users into importing their existing wallets and stealing their mnemonic phrases or private keys.
All these extensions directly require users to enter their mnemonic phrases, while 13 are tampered versions of Rabby that send data to external servers when users save their wallet account information.
Five other extensions collect saved credentials and clipboard content. Socket also discovered that at least nine malicious extensions previously operated as
sports score apps (football, basketball, NBA, etc. This is goes for all we gamblers), accumulating users and reviews before updating and replacing them with wallet-stealing code. In addition, 37 extensions disguised themselves as password generators, VPNs, currency converters, etc., actually running sports score programs. Socket warns that if users have entered mnemonic phrases or private keys in these extensions, their wallet credentials have been permanently compromised.
Uninstalling the extension alone cannot undo the leaked mnemonic phrases or private keys; users should immediately transfer their assets to a new secure created wallet.