Over 40 malicious Firefox extensions impersonating mainstream encryption wallets like MetaMask can steal user credentials.

Gate News bot message, security researchers have discovered a large-scale cybercrime operation that uses dozens of fraudulent Firefox browser extensions to steal users' Crypto Assets Wallet credentials.

Koi Security issued a report on Wednesday warning that this complex attack plan involves more than 40 malicious extensions that masquerade as legitimate wallet applications from popular crypto asset platforms.

Specifically, these fake extensions impersonate legitimate tools of mainstream crypto asset services such as MetaMask, Phantom, Exodus, Keplr, MyMonero, Leap, Ethereum Wallet, and Filfox. After users install these counterfeit extensions, they secretly collect sensitive wallet information, potentially putting the victims' crypto assets at risk of theft.

The report states that this attack "is still ongoing and very active," with some extensions still available. The report adds: "We can confirm that this activity has been active at least since April 2025. Just last week, new malicious extensions were uploaded to the Firefox Add-ons Store. The persistence of these uploads indicates that the operation remains active, ongoing, and continuously evolving."

Source: The Block

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)