Close Menu
AsiaTokenFundAsiaTokenFund
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
What's Hot

Solana Price Analysis: Can Rising Institutional Demand Reverse Bearish Outlook?

July 3, 2025

Ethereum Looks Strong Despite Volatility – $10,000 Price Target Gains Momentum

July 3, 2025

Bitcoin Demand Wanes: Fakeout or Parabolic Rally Ahead?

July 3, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) YouTube LinkedIn
AsiaTokenFundAsiaTokenFund
ATF Capital
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
AsiaTokenFundAsiaTokenFund

40+ Fake Firefox Wallet Extensions Are Stealing Your Crypto, Koi Security Warns

0
By Aggregated - see source on July 3, 2025 Blockchain
Share
Facebook Twitter LinkedIn Pinterest Email

Crypto Journalist

Anas Hassan

Crypto Journalist

Anas Hassan

About Author

Anas is a crypto native journalist and SEO writer with over five years of writing experience covering blockchain, crypto, DeFi, and emerging tech.

Share

Last updated: 

July 3, 2025


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

Koi Exposes 40+ Malicious Crypto Wallet Extensions in Firefox Store Targeting Seed Phrases

Cybersecurity firm Koi Security has uncovered a large-scale malicious campaign involving over 40 fake Firefox extensions designed to steal crypto wallet credentials from unsuspecting users.

The malicious extensions impersonate legitimate wallet tools from well-known platforms, including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox.

According to Koi Security, the campaign has been active since at least April 2025, with new malicious extensions uploaded to the Firefox Add-ons store as recently as last week.

The extensions extract wallet credentials directly from targeted websites and transmit them to remote servers controlled by attackers.

Notably, OKX has previously warned users in January about fake OKX Wallet Firefox extensions, confirming the exchange had not released any Firefox plugins.

The exchange filed complaints with Firefox officials, requesting the removal of the fraudulent browser extensions, while advising users to transfer their wallet assets immediately if they had installed malicious plugins.

Sophisticated Trust-Building Tactics Fool Thousands of Users

The malicious campaign employed sophisticated trust-building mechanisms to increase installation rates and avoid immediate detection.

Many extensions featured hundreds of fake 5-star reviews that far exceeded their actual user bases, creating the appearance of widespread adoption and positive community feedback.

Koi Exposes 40+ Malicious Crypto Wallet Extensions in Firefox Store Targeting Seed Phrases
Source: Koi Security

Threat actors carefully mimicked legitimate wallet tool branding, using identical names and logos to real services they impersonated.

This visual similarity increased the likelihood of accidental installations by users searching for official cryptocurrency wallet extensions.

The attackers exploited the open-source nature of legitimate wallet extensions by cloning authentic codebases and inserting malicious logic.

This approach allowed them to maintain expected user experiences while secretly exfiltrating sensitive wallet data in the background.

This strategy reduced development time while increasing the likelihood that security tools would miss malicious modifications to otherwise legitimate code.

Some malicious extensions remained undetected for extended periods due to their functional similarities to legitimate wallet tools.

Users experienced standard wallet functionality while their credentials were simultaneously transmitted to an attacker-controlled infrastructure.

Hardware and Software Attacks Expand Beyond Browser Extensions

The Firefox extension campaign represents one vector in an expanding ecosystem of cryptocurrency theft methods targeting both software and hardware security measures.

According to a recent report by Cryptonew, a Chinese crypto investor lost nearly $7 million after purchasing a fake cold wallet through Douyin, TikTok’s Chinese platform.

The sophisticated hardware trap compromised the wallet’s private key generation at the fundamental level.

When the victim initialized the device, it generated keys already known to attackers, creating a false sense of security while providing criminals complete access to funds.

Similarly, Cybersecurity firm Moonlock recently warned about fake Ledger Live applications targeting macOS users through the Atomic macOS Stealer malware.

The malware embedded across at least 2,800 compromised websites replaces genuine Ledger Live applications with fake versions that harvest seed phrases through convincing pop-ups.

Attackers are also expanding their reach beyond hardware and software. Physical phishing attacks have emerged through traditional mail systems, with scammers impersonating Ledger and sending fake letters via USPS.

The letters urge users to “validate” their wallets through QR codes that link to phishing sites designed to steal private keys.

This latest discovery adds to the growing threat from sophisticated attackers to the crypto industry.

Crypto investors lost more than $2.2 billion to hacks, scams, and security breaches in the first half of 2025 alone, according to CertiK’s security report.

Wallet-related breaches alone accounted for $1.7 billion across just 34 attacks, while phishing followed with over $410 million stolen in 132 incidents.

Ethereum remained the most targeted blockchain, experiencing 175 security events and over $1.6 billion in losses.

The largest hack occurred in February when crypto exchange Bybit suffered a breach resulting in theft of more than $1.5 billion in liquid-staked ETH and MegaETH.

Code vulnerabilities caused $229 million in damages during May 2025 alone, representing a massive jump from just $5 million in April.

Physical “wrench attacks” targeting crypto holders have surged globally, with at least 32 reported incidents in 2025, putting the year on pace to surpass 2021’s record of 36 attacks.


Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Hackers Steal $180M from Brazilian Banking System in Largest-Ever Attack, Cash Out via Bitcoin and USDT

July 3, 2025

GeForce NOW Expands Cloud Gaming Library with Exciting July Releases

July 3, 2025

Tether Partners with Adecoagro for Renewable-Powered Bitcoin (BTC) Mining in Brazil

July 3, 2025
Leave A Reply Cancel Reply

What's New Here!

Solana Price Analysis: Can Rising Institutional Demand Reverse Bearish Outlook?

July 3, 2025

Ethereum Looks Strong Despite Volatility – $10,000 Price Target Gains Momentum

July 3, 2025

Bitcoin Demand Wanes: Fakeout or Parabolic Rally Ahead?

July 3, 2025

Nano Labs Loads Up on BNB With Ambitious $1B Treasury Target

July 3, 2025
AsiaTokenFund
Facebook X (Twitter) LinkedIn YouTube
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
© 2025 asiatokenfund.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.