---
The Tactics: Deception and Technical Tricks
The hackers employed a classic strategy: gain trust first, then strike. They published seemingly useful extensions—for sports scores or weather data—accumulating positive reviews and high download numbers. But the real trick came later: in subsequent versions, malicious code was surreptitiously embedded. Thanks to automatic updates, users were infected without realizing it, putting those who had stored wallet secrets (seed phrases or private keys) in browser extensions in grave danger.
The extensions used particularly clever evasion techniques:
- Dynamic code injection: Malicious code activated only after download and frequently changed its signature.
- Sandbox checks: The malware verified whether it was running in a test environment before activating.
- Targeted attacks: Extensions scanned browser storage for common wallet files (e.g., from MetaMask, Phantom, or Trust Wallet) and exfiltrated the data to external servers.
---
The Consequences: Stolen Secrets Remain a Threat
Socket monitored this campaign for months and published a detailed analysis on June 10, 2024. The researchers warn: even after uninstalling the extensions, wallet secrets remain vulnerable. Many users had saved their seed phrases or private keys directly within the extensions—a practice security experts have long condemned as extremely risky.
In total, 40 different add-ons were identified, all using the same tactics. Together, they had over 1.3 million downloads—a staggering figure that highlights just how much users trust seemingly
harmless tools. While Mozilla quickly removed the malicious extensions (including "Sports Score Live," "Weather Forecast," and "Crypto Tracker") from the Firefox add-on store, the threat persists for anyone who installed them before removal.
---
What Affected Users Should Do
If you’ve installed any of the infected extensions, act immediately:
1. Uninstall the extension—even if the malware was already active.
2. Treat all wallet secrets as compromised—even after removing the extension.
3. Create new wallets and transfer your seed phrases/keys to a fresh, secure wallet.
4. Monitor transactions: Check your wallet addresses for suspicious activity.
5. Enable two-factor authentication (2FA) if not already active.
---
Why Browser Extensions Are a Hacker’s Dream
The issue lies in the design of many crypto wallets: users often store access credentials directly in browsers or extensions—a convenient but extremely dangerous practice. Hackers exploit this weakness, targeting:
- Browser-based wallets (e.g., MetaMask in browser mode)
- Extensions promising wallet integration (e.g., "Crypto Dashboard")
- Tools for managing seed phrases
Experts strongly advise against storing wallet secrets in browser extensions or even browser storage. Instead, they recommend:
- Using hardware wallets (Ledger, Trezor) for long-term storage.
- Creating dedicated browser profiles for crypto activities.
- Maintaining regular backups stored offline.
---
Mozilla Responds—But User Responsibility Remains Key
Mozilla removed the malicious extensions from the Firefox add-on store and is collaborating with Socket to prevent similar attacks in the future. Ultimately, however, security depends on the user. The crypto community must recognize that any extension could be an entry point for attackers.
---
Conclusion: A Wake-Up Call for Rigorous Crypto Security
This attack is yet another reminder of how critical a strong security culture is in the crypto world. If you truly want to protect your digital assets, stick to proven best practices—and never recklessly expose your wallet secrets. Stay safe!
📰 Read more
→ Zerohash Doubles Down: Second Attempt for OCC Bank License→ GTA VI on Solana? Take-Two’s SEC Filings Fuel Speculation→ LayerZero Launches Trading Infrastructure for Crypto and Tokenized Markets