Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
Malicious Firefox Extensions Stole  Million Cryptocurrency

Malicious Firefox Extensions Stole $1 Million Cryptocurrency

by Tekmono Editorial Team
12/08/2025
in News
Share on FacebookShare on Twitter

A recent malicious campaign, “GreedyBear,” has stolen an estimated one million dollars from cryptocurrency wallet owners using around 150 malicious Firefox extensions, according to Koi Security.

The scheme involved threat actors impersonating legitimate cryptocurrency wallet extensions within the Firefox add-ons store. Mozilla has since removed the identified malware. However, researchers suggest that attackers could swiftly launch similar campaigns, with a potential expansion of “GreedyBear” already identified in the Chrome web store through an extension named Filecoin Wallet.

The malicious extensions initially appeared benign, with threat actors uploading seemingly harmless crypto wallet extensions with branding that mimicked popular platforms such as MetaMask, TronLink, and Rabby. They then accumulated fake positive reviews to build trust. Subsequently, attackers replaced the names and logos and injected malicious code, transforming these extensions into keyloggers. These compromised extensions were capable of capturing form field inputs and victims’ external IP addresses, transmitting this sensitive data to attackers’ servers.

Related Reads

Google opens applications for Gemini App Trusted Tester program

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

To safeguard against such threats, users are advised against blindly trusting extensions found in official add-on stores. Before installing a new extension, it is crucial to thoroughly read user reviews beyond just star ratings, examine the version history, and scrutinize the developer’s other projects for any suspicious activity. For cryptocurrency wallets specifically, a safer practice is to navigate directly to the project’s official website, which will provide a link to the legitimate extension.

ShareTweet

You Might Be Interested

Google opens applications for Gemini App Trusted Tester program
News

Google opens applications for Gemini App Trusted Tester program

17/06/2026
Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
News

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

17/06/2026
Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
News

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

17/06/2026
SpaceX acquires AI coding startup Cursor for  billion in strategic move
News

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

17/06/2026
Please login to join discussion

Recent Posts

  • Google opens applications for Gemini App Trusted Tester program
  • Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
  • Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
  • SpaceX acquires AI coding startup Cursor for $60 billion in strategic move
  • Qualcomm unveils Snapdragon Reality Elite as next-gen XR platform

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.