The security company Socket disclosed that there had recently been a malicious expansion of Firefox platform disguised as encrypted wallets. The researchers linked 77 of these extended identities to the same round of delivery activities, and 40 were identified as having malicious acts aimed at the encryption wallet users ' assistive words, private keys and account data.

Concealed as mainstream wallet induced import

These extensions impersonate Web3 products such as OKX, Rabbi Wallet, TronLink, with similar names and interfaces to the original height, and are easily misperceptive by users. About half of the samples display seemingly normal wallet pages and direct users to import existing wallets. Information is stolen directly as soon as it is entered as a reference or a private key.

Socket also found 13 other samples based on a modified version of Rabbi Wallet. They function normally on the surface but send information to an external server when the user saves wallet account data. There are also 5 extensions that collect the contents of the vouchers and clipboard that are saved in the browser.

Some of the plug-ins will be compared and turned to currency theft

According to researchers, there were also 37 extended surface-packaged password generator, dark-colour model tool, VPN, exchange rate converter and note application, which actually operated a sports score and shared the same set of dead sports data service vouchers.

Nine of these have been identified as malicious expansions, initially in the form of a football, basketball, NBA or American football score, followed by an updated version of the code that replaces the wallet information. This would take over the original installation and evaluation records and reduce user vigilance. Socket named the round "Offside Wallet Theft Actory" but indicated that it had not been confirmed that all extensions were controlled by the same operator.

There's also a high risk of limited access.

Socket mentions that an expansion of fake OKX only applies for both store and tabs because it does not require a proactive search of data in the browser, but rather loads a remote page, waiting for the user to enter a self-entry aid. This means that it is not enough to judge the security of an extension application on the basis of the extent of its competence.

The researchers indicated that all users who had entered assistive words or private keys in those extensions should be considered to have permanently disclosed the information on the wallet. Even if the offload extension was not able to withdraw the data already sent, the assets would need to be moved to the new wallet as soon as possible.

The browser extension has become a common entry point for the theft of encrypted assets. Prior to this, there was a malicious expansion of a long-term fee charged to Solana traders, and the assailants hid their secret programs into pirated software, disguised Mac clipboard applications and PC games distributed through Steam.