Forty fake wallet extensions flooded Firefox's store, phishing seed phrases
The FoxyWallet campaign cloned MetaMask, Coinbase and Trust Wallet add-ons, padding each with hundreds of fake five-star reviews to harvest keys, Koi Security found.
A browser extension that manages a crypto wallet must be trusted with the most sensitive secret you own: the seed phrase that controls your funds. Extensions run with deep access to the pages you open, which is what makes a malicious one so dangerous. In mid-2025, researchers at Koi Security found more than 40 extensions in Mozilla's official Firefox Add-ons store abusing exactly that trust.
Cloned code, hidden theft
The campaign, which Koi named FoxyWallet, impersonated at least a dozen well-known wallets — among them MetaMask, Coinbase, Trust Wallet, Phantom, Exodus, OKX, Keplr and Bitget, per Koi Security. The attackers did not build fakes from scratch. They cloned the wallets' real open-source code and injected malicious logic, so each extension behaved normally while quietly pulling wallet keys and seed phrases from the sites victims visited and sending them, along with the victim's IP address, to a remote server.
Built to look legitimate
What made the listings convincing was manufactured social proof. Each carried the same name and logo as the genuine tool and hundreds of fake five-star reviews — far more than the number of real installs, Koi Security said — the kind of rating wall most users skim and trust. The Hacker News reported the campaign had run since at least April 2025, with fresh uploads appearing weeks before it was disclosed.
Russian-language comments in the code, and metadata from a PDF left on a command-and-control server, point to a Russian-speaking threat actor, per Koi Security. Mozilla removed all but one of the flagged extensions once they were reported, The Hacker News said, and the browser maker has described an early-detection system meant to catch crypto-drainer extensions before they gain traction.
Before you install a wallet extension
- Install only by following the official link from the wallet's own website; do not search the store by brand name and trust the top result.
- Discount star ratings and review counts as trust signals — both were entirely faked in this campaign, per Koi Security.
- Check the publisher and install count, and be wary of a brand-name wallet offered by a tiny or brand-new developer.
- Never type an existing seed phrase into a freshly installed extension; treat any such prompt as theft in progress.
- Keep large balances in a hardware wallet, and periodically review and remove extensions with access to your browser.
The Firefox store is curated, yet dozens of drainers still slipped through for months — a reminder that a marketplace's presence is not an endorsement. With wallet software, the safest link is the one published by the wallet's own developers, not the one with the most stars.
— Sources: [Koi Security](https://www.koi.ai/blog/foxywallet-40-malicious-firefox-extensions-exposed) · [The Hacker News](https://thehackernews.com/2025/07/over-40-malicious-firefox-extensions.html)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING