Fake Rabby, OKX Extensions Steal Recovery Phrases
Researchers found 16 malicious Firefox extensions posing as Rabby and OKX wallets, capable of extracting recovery phrases and private keys from cryptocurrency users.

Researchers have discovered 16 malicious Firefox extensions impersonating Rabby Wallet and OKX Wallet, each capable of extracting recovery phrases and private keys from the users who install them. The extensions targeted two specific, widely recognized cryptocurrency wallets rather than inventing new tools, which is the detail worth sitting with for a moment.
The attack surface
Browser extensions for cryptocurrency wallets operate under a broad permission set by necessity. Legitimate wallet extensions need to read page context, handle cryptographic material, and communicate with signing APIs. Malicious ones exploit the same permissions for the same reasons the real tools need them.
The sixteen-extension cluster worked by impersonating Rabby Wallet and OKX Wallet closely enough that users searching for those tools might not distinguish them from the originals. Both wallets have real Firefox add-ons; a convincing lookalike with a similar name, icon, and review count is the kind of gap that static store review processes were not designed to close.
The scale matters here. One malicious extension is a single exposure point, removable after detection. Sixteen extensions are sixteen independent distribution channels: sixteen listings, sixteen review cycles, and considerably more time for at least some of them to remain available while others are pulled.
A recurring structural problem
This is not the first time this class of attack has worked, and it will not be the last, because the incentive structure for browser extension stores has not changed. Review happens at submission time. Behavioral exfiltration can trigger conditionally at runtime, after the extension is installed and the review process is finished.
The September 2026 BragJack findings laid out how much latitude extension code has inside a loaded page context. Wallet extensions sit at the extreme end of that trust model: they handle seed phrases, which are the single most sensitive credential a cryptocurrency user holds.
Unlike a password, a recovery phrase cannot be changed after the wallet is created. Compromise is permanent. Every asset derived from a compromised phrase is at risk indefinitely, regardless of whether the device is cleaned up afterward.
What affected users should do
Anyone who installed one of the identified extensions should treat the recovery phrase as exposed and move all assets to a new wallet created on a clean device. Extension removal does not reverse exfiltration that has already occurred.
For verification going forward: Rabby Wallet and OKX Wallet both publish official add-on links on their respective websites. The extension ID is the only check that cannot be spoofed with patience; names, icons, and review counts can all be replicated. Cross-referencing the ID against the developer’s official listing takes thirty seconds and is worth the habit.
The Firefox add-ons team was notified, per The Hacker News reporting.
Found this useful? Share it.


