Skip to content

16 Firefox Extensions Posing as Rabby and OKX Wallets Steal Recovery Phrases

Socket found 16 Firefox extensions posing as Rabby and OKX wallets that send recovery phrases and private keys to attacker-run Cloudflare Workers.

Fake Rabby Wallet Firefox extension screens prompting the user to import a seed phrase
Fake Rabby Wallet Firefox extension · Credit: Socket

Sixteen Firefox extensions posing as Rabby and OKX crypto wallets captured recovery phrases and private keys as people typed them in, then passed the secrets to servers run by the attackers. The listings were dressed as wallet portals, desktop utilities and browser tools.

The set was found by researchers at Socket, which ties it with high confidence to an August crypto-theft extension campaign. The impersonated wallets have real followings, Socket notes: 900,000 Chrome Web Store users for Rabby and more than 1,000,000 for OKX Wallet. Mozilla had pulled all 16 from Firefox by October 5, the firm says. That does not help anyone who already entered a real phrase into one of them.

Four of the Firefox packages were full copies of Rabby Wallet, the Ethereum wallet. Each ran to 1,114 files, and the branding was changed to Raabby WaIIet, with capital I's standing in for the lowercase L's. The clones kept the real wallet's import screens and added a hook behind each one. Whenever a user imported a mnemonic or private key, the extension forwarded the same secret to a Cloudflare Worker. It did so inside the address of a GET request, so the phrase could also end up in request logs along the way.

The other twelve Firefox extensions leaned on OKX Wallet. Their label was a generic Portal WALLET, but the interface came from OKX and pointed to OKX's own help pages, borrowing the real brand's credibility. The screen asked for a 12 or 24 word phrase. Eleven registered a background script that posted whatever was entered. The twelfth, sipoo-grozza@browserweb.com, never loaded its script because of a manifest gap and a mismatched message name. Socket still counts it as hostile, since the theft code shipped inside it and a repaired manifest would switch it on.

Every Firefox manifest declared that the extension collected no data, and the code said otherwise. The declaration protected nobody. It is a field the publisher fills in, so it works as a prompt for suspicion at most, never as a safeguard. One background script went further: a code comment claimed only a hash and a word count left the device, while the payload carried the raw phrase. Socket reads that contradiction as concealment.

Socket's advice for anyone who entered a real recovery phrase or private key into one of these extensions is blunt. Treat the wallet as compromised, create a new one from a clean device and move the assets. Changing the extension password changes nothing, because the phrase itself is what the attackers now hold.

Share this story

Isabella Conti

Isabella Conti writes for the techshooked news desk, covering general technology news from product launches to industry shifts. Her standard is plain: verify before publishing, cite the primary source, and tell readers why a development matters without overstating it.