Security researchers have identified a group of 16 malicious Mozilla Firefox extensions impersonating well-known cryptocurrency wallets, including Rabby and OKX Wallet. The add-ons intercept users' recovery phrases and private keys during the wallet import process and attempt to exfiltrate those credentials to attacker-controlled infrastructure.
According to The Hacker News, which reported the findings, the extensions are disguised as legitimate wallet portals, desktop utilities, and general browser tools. Their malicious code activates at the precise moment a user pastes or types a recovery phrase or private key — on the import or restore screen — and silently works to send those secrets outward.
Why Placement Matters More Than Code
The sophistication of this attack lies less in obfuscation and more in positioning. A cryptocurrency recovery phrase is, in effect, a complete backup of the wallet: anyone holding it can derive the private keys and drain funds on any device, at any time, with no further authentication required. That means an attacker does not need to defeat encryption or rely on heavy code tricks — it is enough to sit exactly where the victim enters their secret, on a screen that looks entirely normal.
Users see no visible sign of compromise at the moment of capture. There is no error message, no redirect, nothing that would tip off a careful observer. This is what makes browser-based seed phrase theft so damaging: the interception happens inside an interface the victim already trusts.
The incident is also a reminder that presence in an add-on repository is not a security guarantee. Review processes can miss extensions whose malicious behaviour is dormant, activated only by a later update, or conditional on the site being visited. Store distribution mitigates some risks, but it does not eliminate them — a weakness the broader add-on ecosystem has struggled with for years.
The Risk Extends Beyond Personal Holdings
The choice of brands is not accidental. Rabby and OKX Wallet are prominent enough to serve as convincing bait for anyone clicking through search results, advertisements, or links forwarded in chat groups. A fake extension promising a familiar wallet experience is precisely the kind of lure that converts curiosity into installation.
The exposure applies to any reader who holds digital assets in a browser-based wallet. On machines used for work — laptops where wallet credentials sit alongside corporate tools and internal systems — a compromised extension raises the stakes considerably. For IT professionals managing endpoint security, a rogue add-on is not merely a crypto problem; it is a browser-hygiene problem that deserves a place in the standard audit checklist.
A Practical Extension Hygiene Checklist
- Install only through official channels. Download wallet software from the wallet's own website and follow the verified listing linked from there. Never install from search advertisements or links forwarded in chat groups and forums.
- Audit what is already installed. Open your browser's add-on manager and review the full list now. Remove anything unfamiliar, with particular attention to recent wallet-related additions and tools you did not deliberately install.
- Treat recovery phrases as permanent credentials. No legitimate wallet, exchange, or support agent will ever ask you to enter a recovery phrase to "sync," "verify," or "recover" an account. Anyone who does is phishing.
- Reduce the blast radius. Consider hardware wallets, which keep signing keys offline, or use a dedicated browser profile for wallet activity so an extension compromise cannot spread to your main session.
- If exposure is suspected, act immediately. A recovery phrase cannot be revoked or invalidated. The only safe response is to generate a fresh wallet in a clean environment and move all assets to it straight away — and never reuse any portion of the old phrase.
Caveat: Removal Status Unconfirmed
The Hacker News coverage does not confirm whether the 16 extensions have been removed from Mozilla's add-on repository, and the specific extension identifiers are not listed in the report reviewed here. Users should monitor Mozilla's security advisories and the official Rabby and OKX channels for updates. Until the status is confirmed, the safe assumption is that similar impersonation attempts will continue to appear — and that personal vigilance remains the most reliable defence.
網絡安全研究人員發現一組共 16 款惡意 Mozilla Firefox 附加元件,假冒知名加密貨幣錢包,包括 Rabby 及 OKX Wallet。這些附加元件會在用戶匯入錢包的過程中截取其助記詞(recovery phrase)及私鑰,並嘗試將這些憑證外洩至攻擊者控制的伺服器。
據報道這項發現的 The Hacker News 指出,這些附加元件以合法錢包入口網站、桌面工具及一般瀏覽器工具的外觀出現;其惡意程式碼會在用戶貼上或輸入助記詞或私鑰的那一刻——即匯入或還原錢包的畫面——被啟動,悄然嘗試將這些機密資料外送。
要害在位置,不在混淆技巧
這宗攻擊的技術含量,與其說在於程式混淆,不如說在於出手的位置。加密貨幣的助記詞,本質上就是錢包的完整備份:持有者可在任何裝置、任何時間派生出私鑰並轉走資金,無需任何進一步驗證。換言之,攻擊者不必破解加密,也不必倚重複雜的程式技巧——只要置身於受害者輸入機密資料的正確位置即可,而那個畫面看起來完全正常。
用戶在資料被擷取的一刻看不到任何可疑跡象:沒有錯誤訊息,沒有重新導向,沒有任何足以引起警覺的線索。正因如此,透過瀏覽器錢包竊取 seed phrase 才如此致命——截取動作就發生在用戶早已信任的介面(UI)之內。
這宗事件亦提醒我們:附加元件在官方商店上架,並不等於獲得安全保證。審核機制可能漏過那些惡意行為仍處於休眠狀態、需待日後的更新才觸發、或只在瀏覽特定網站時才啟動的附加元件。商店分銷可以降低部分風險,卻無法完全消除風險——這是整個附加元件生態多年來一直未能解決的弱點。
風險不止於個人持倉
品牌的選擇並非偶然。Rabby 及 OKX Wallet 的知名度,足以令點擊搜尋結果、廣告或聊天群組轉發連結的人放下戒心;一個聲稱提供熟悉錢包體驗的假附加元件,正是把一時好奇轉化為安裝行動的典型誘餌。
這類風險適用於所有在瀏覽器錢包中持有數碼資產的用戶。在日常工作所用的電腦上——錢包資料與公司工具、內部系統並存的手提電腦——一個被入侵的附加元件,會令後果嚴重得多。對負責端點安全(endpoint security)的 IT 專業人士而言,一個惡意附加元件不單是加密貨幣的問題,更是瀏覽器衛生問題,應該納入標準審計清單。
實用的附加元件衛生清單
- 只從官方渠道安裝。 從錢包官方網站下載軟件,並只安裝網站上提供驗證的商店連結。切勿安裝來自搜尋廣告、聊天群組或論壇轉發連結的版本。
- 檢視已安裝的附加元件。 立即打開瀏覽器的附加元件管理介面(add-on manager),逐一審視已安裝清單。移除任何不熟悉的項目,尤其留意近期新增的錢包相關工具,以及你從未主動安裝的軟件。
- 把助記詞視為永久的登入憑證。 任何合法的錢包、交易所或客服人員都絕對不會要求你輸入助記詞來「同步」、「驗證」或「還原」帳戶。任何人這樣做,就是在釣魚。
- 縮小爆炸半徑。 考慮使用 hardware wallet,把簽署私鑰保持離線;或為錢包操作另開專用瀏覽器 profile,令附加元件一旦被入侵也不會波及主瀏覽器環境。
- 一旦懷疑已外洩,立刻行動。 助記詞無法被撤銷或作廢。唯一安全的處理方式,是立即在一個乾淨的環境中產生新的錢包,把所有資產轉移過去——並切勿重用舊助記詞的任何一部分。
附註:附加元件的下架狀態未獲確認
The Hacker News 的報道並未證實那 16 款附加元件是否已從 Mozilla 的附加元件商店(add-ons repository)下架,而報告亦未列出具體的附加元件識別碼。用戶應持續留意 Mozilla 的安全公告,以及 Rabby 和 OKX 的官方頻道。在狀態確認之前,最穩妥的假設是:同類的假冒嘗試仍會繼續出現——個人警覺始終是最可靠的防禦。
