Socket today disclosed a batch of malicious Firefox extensions: 40 confirmed ones are stealing wallets or credentials, with another 37 linked to the same distribution network.
More notable than “fake wallet listings” is that some extensions start out as sports score or ordinary utility apps, then reuse the same Firefox ID and, through version updates, turn into wallet-stealing malware. What users see when they first install it may indeed look legitimate.
This is the supply-chain risk for browser wallets: you’re trusting not only the installer, but also the publisher account, subsequent automatic updates, and the remote content that gets loaded when the extension runs. Verifying only the name and rating at install time proves that it looks normal then, but it can’t guarantee that it will still be normal six months later.
Among them, 13 modified Rabby extensions will exfiltrate the keyring before it’s encrypted locally. This detail runs against common sense: even if the wallet claims “data is encrypted locally,” as long as malicious code is inserted before encryption, it can still obtain the plaintext.
My approach is to separate assets from the browser: keep only small amounts in high-frequency interaction wallets; don’t store long-term assets in everyday browser extensions; and periodically review the extensions list, publishers, and changes in recent versions. If an icon, permissions, or interface suddenly changes, disable it first—don’t rush to enter the recovery phrase for verification.
Official stores can reduce the cost of filtering, but they can’t continuously validate the update chain for you.
How often do you check the wallet extensions in your browser?
More notable than “fake wallet listings” is that some extensions start out as sports score or ordinary utility apps, then reuse the same Firefox ID and, through version updates, turn into wallet-stealing malware. What users see when they first install it may indeed look legitimate.
This is the supply-chain risk for browser wallets: you’re trusting not only the installer, but also the publisher account, subsequent automatic updates, and the remote content that gets loaded when the extension runs. Verifying only the name and rating at install time proves that it looks normal then, but it can’t guarantee that it will still be normal six months later.
Among them, 13 modified Rabby extensions will exfiltrate the keyring before it’s encrypted locally. This detail runs against common sense: even if the wallet claims “data is encrypted locally,” as long as malicious code is inserted before encryption, it can still obtain the plaintext.
My approach is to separate assets from the browser: keep only small amounts in high-frequency interaction wallets; don’t store long-term assets in everyday browser extensions; and periodically review the extensions list, publishers, and changes in recent versions. If an icon, permissions, or interface suddenly changes, disable it first—don’t rush to enter the recovery phrase for verification.
Official stores can reduce the cost of filtering, but they can’t continuously validate the update chain for you.
How often do you check the wallet extensions in your browser?