Sixteen Firefox extensions posing as Rabby and OKX crypto wallets captured recovery phrases and private keys as people typed them in, then passed the secrets to servers run by the attackers. The listings were dressed as wallet portals, desktop utilities and browser tools.
The set was found by researchers at Socket, which ties it with high confidence to an August crypto-theft extension campaign. The impersonated wallets have real followings, Socket notes: 900,000 Chrome Web Store users for Rabby and more than 1,000,000 for OKX Wallet. Mozilla had pulled all 16 from Firefox by October 5, the firm says. That does not help anyone who already entered a real phrase into one of them.
Four of the Firefox packages were full copies of Rabby Wallet, the Ethereum wallet. Each ran to 1,114 files, and the branding was changed to Raabby WaIIet, with capital I's standing in for the lowercase L's. The clones kept the real wallet's import screens and added a hook behind each one. Whenever a user imported a mnemonic or private key, the extension forwarded the same secret to a Cloudflare Worker. It did so inside the address of a GET request, so the phrase could also end up in request logs along the way.
The other twelve Firefox extensions leaned on OKX Wallet. Their label was a generic Portal WALLET, but the interface came from OKX and pointed to OKX's own help pages, borrowing the real brand's credibility. The screen asked for a 12 or 24 word phrase. Eleven registered a background script that posted whatever was entered. The twelfth, sipoo-grozza@browserweb.com, never loaded its script because of a manifest gap and a mismatched message name. Socket still counts it as hostile, since the theft code shipped inside it and a repaired manifest would switch it on.
Every Firefox manifest declared that the extension collected no data, and the code said otherwise. The declaration protected nobody. It is a field the publisher fills in, so it works as a prompt for suspicion at most, never as a safeguard. One background script went further: a code comment claimed only a hash and a word count left the device, while the payload carried the raw phrase. Socket reads that contradiction as concealment.
Socket's advice for anyone who entered a real recovery phrase or private key into one of these extensions is blunt. Treat the wallet as compromised, create a new one from a clean device and move the assets. Changing the extension password changes nothing, because the phrase itself is what the attackers now hold.













