Socket Identifies 40 Malicious Firefox Add-Ons Targeting Crypto Users
Key Takeaways
- •Socket identified 40 malicious Firefox add-ons that were aimed at cryptocurrency holders and disguised as legitimate extensions.
- •Researchers said the activity was a coordinated campaign rather than a single isolated malicious listing.
- •Some malicious code was delivered through routine updates after users had already installed and trusted the extensions.
- •Browser extensions can access sessions, pages, and wallet tools, creating risks of seed phrase theft, credential harvesting, and unauthorized transfers.
- •Security vendors advise users to remove unrecognized extensions, scrutinize permissions, and keep larger holdings in hardware wallets.

Security research firm Socket has identified 40 malicious Firefox add-ons designed to steal cryptocurrency wallet access and drain funds, a fresh warning for anyone who manages digital assets through a web browser.
What Socket Found in the Firefox Add-On Campaign
Socket identified 40 malicious Firefox add-ons built to prey on cryptocurrency holders, according to The Hacker News. The extensions posed as legitimate tools inside the Firefox add-on ecosystem. Socket made its name scanning open-source code packages for supply-chain attacks, and browser extensions pose a similar problem: a trusted delivery channel for software that runs with broad access to what a user does online.
The add-ons were engineered to reach crypto wallets, the software people use to store and send digital coins. Researchers described the effort as a coordinated campaign rather than a single rogue listing, Cybernews reported.
Some of the malicious code hid behind ordinary-looking add-ons and rode in through routine updates, according to a related investigation into Firefox wallet malware detailed by CryptoSlate. That approach let bad code slip in after a user had already trusted the extension. It mirrors tactics from earlier documented cases, in which previously legitimate extensions with installed user bases were sold or hijacked and then updated with malicious code — meaning a store's initial review offers little protection against what an add-on later becomes.
Why Crypto Users Are Prime Targets for Malicious Extensions
A browser extension sits very close to what a user does online. It can watch sessions, read pages, and interact with the wallet tools running inside the browser. That closeness is the danger: a malicious add-on can attempt to capture a seed phrase — the secret backup words that unlock a wallet — or trick a user into approving a transfer they never intended.
Crypto users are high-value targets because stolen wallet access converts to money quickly. Once funds leave a wallet, transactions are hard to reverse, unlike a fraudulent card charge that a bank can claw back.
Phishing is the other risk. A fake extension can impersonate a real wallet or exchange login, harvesting the credentials a user types in. These browser-level attacks matter because they bypass the wallet's own security entirely.
What This Means for Crypto Security
A campaign spanning 40 add-ons points to scale rather than an isolated mistake. It fits a persistent pattern of attackers chasing wallet and exchange access — the same pressure that keeps regulators drafting new crypto asset rules and pushing exchanges toward tighter safeguards. Extension marketplaces, including both Mozilla's and Google's stores, have repeatedly removed crypto-targeting malware in past incidents, and Mozilla maintains a blocklist that can remotely disable malicious add-ons in users' browsers once they are identified.
For a regular holder, the practical steps are straightforward. Open the Firefox add-ons menu and review every installed extension, removing anything unrecognized or no longer needed. Be cautious with permissions: treat any add-on that asks to interact with a wallet or read every page with suspicion, and only install extensions from trusted, well-reviewed publishers such as those listed on Mozilla's official add-ons directory. Security vendors have long recommended keeping larger, long-term holdings in hardware wallets, which store private keys offline where browser malware cannot reach them.
Theft of crypto through malware sits alongside broader enforcement stories, including expanding sanctions tied to crypto payments. The common thread is that digital assets remain a magnet for bad actors, so the burden of caution falls heavily on the individual user. For anyone holding even a small amount of crypto in a browser wallet, this discovery is a prompt to audit extensions today — and to follow the research channels that exposed this campaign for any further disclosures as the findings circulate.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.