Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Fake Rabby and OKX Wallet Clones Found Stealing Crypto Seed Phrases via Firefox Add-ons
Fake Rabby and OKX Wallet Clones Found Stealing Crypto Seed Phrases via Firefox Add-ons
Read Time:3 Minute, 29 Second

A wave of 16 malicious Firefox extensions disguised as cryptocurrency wallet tools has been caught siphoning recovery phrases and private keys straight out of victims’ browsers, according to new research from Socket.dev. The add-ons impersonated the popular Rabby Wallet and OKX Wallet, cloning their real interfaces closely enough that users had little reason to suspect anything was wrong before typing in the exact secrets that protect their crypto holdings.

Cloned Wallets, Hidden Theft Code

Socket’s researchers found two distinct families within the campaign. Four extensions were large, near-complete clones of Rabby Wallet, each one bundling more than a thousand files to recreate the legitimate app’s account management screens, transaction interfaces, and wallet-import flow. The other twelve were smaller add-ons styled after OKX Wallet, presented under generic “portal” branding. Of those twelve, eleven contained active background scripts built to steal credentials, while a twelfth held similar theft logic that was never wired up correctly and couldn’t actually execute.

What made the fake Rabby extensions particularly convincing is that the attackers didn’t just skin a phishing page — they repackaged a working wallet application, left some genuine Rabby and DeBank service links intact, and quietly inserted data-theft routines directly after the screens where a user enters a 12-word or 24-word seed phrase, or a 64-character private key. The wallet continued to function normally from the victim’s point of view, while a hidden handler copied the exact secret being entered.

Where the Stolen Data Went

Once captured, recovery phrases and keys were relayed to attacker-controlled Cloudflare Workers endpoints — infrastructure that’s cheap to spin up and blends in with ordinary web traffic. The Rabby-clone variants transmitted stolen phrases embedded in GET request URLs, with a backup delivery method if the first attempt failed; this method is notable because it can leave recovery phrases sitting in plaintext inside logs on systems far beyond the attacker’s own servers. The OKX-styled extensions instead used HTTPS POST requests carrying JSON payloads, and one variant offered three separate exfiltration paths, including a tracking-pixel-style image beacon, apparently to maximize the odds that at least one method got through.

Socket also noted a telling bit of deception: every single one of the 16 extensions declared in its own privacy disclosure that it collected no user data whatsoever — directly contradicted by the code quietly harvesting seed phrases in the background.

Linked to an Earlier Campaign

This isn’t the threat group’s first run at Firefox users. Socket said it was able to connect the new wave to an earlier campaign from August with high confidence, citing overlapping code, shared hosting infrastructure, and a common tracking identifier embedded across samples. Mozilla removed the malicious listings from its add-on marketplace by October 5, 2026, but that cleanup only stops new victims from installing the extensions — anyone who already entered real wallet secrets into a working copy remains exposed regardless of whether the listing still exists.

What Affected Users Should Do

Because a stolen seed phrase or private key can’t be “revoked” the way a password can, Socket’s guidance for anyone who may have used one of the fake wallets is to assume full compromise and act accordingly:

  • Uninstall any of the identified malicious extensions immediately.
  • Treat any wallet whose recovery phrase or private key was entered into a flagged extension as fully compromised.
  • Generate a brand-new wallet on a clean, trusted device rather than reusing the exposed one.
  • Move all funds and assets to the new wallet as quickly as possible.
  • Revoke any token approvals previously granted from the compromised wallet address.

Security teams reviewing browser inventories, synced extension lists, and network logs for signs of this campaign should search for the associated Cloudflare Workers endpoints and file hashes Socket published, while taking care never to paste an actual recovery phrase into a ticket, alert, or case note. The broader lesson echoes a pattern seen repeatedly in crypto-targeted malware: a wallet interface that looks exactly right is not proof that it is, and any extension — however polished — should be verified through the browser’s official store listing and developer reputation before trusted secrets ever touch it.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Fake Rabby and OKX Wallet Clones Found Stealing Crypto Seed Phrases via Firefox Add-ons, use the discussion on Forum.

>> forum community

Comments

Leave a Reply