News View Non-AMP

Chrome And Firefox Users Targeted in Coordinated Crypto Credential Attacks

Published by
Elena R and Qadir AK

Popular web browsers Google Chrome and Mozilla Firefox are facing serious security threats. While Chrome is being targeted through a dangerous zero-day vulnerability, Firefox users are under attack from a slew of harmful browser extensions.

On July 1, cybersecurity experts uncovered a malicious campaign involving 45 fake Firefox extensions designed to steal cryptocurrency wallet details from unsuspecting users.

Malicious Firefox Extensions Mimicking Crypto Wallets

The 45 malicious Firefox extensions impersonate legitimate crypto wallet tools from widely used platforms such as Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox. A security researcher at Koi Security, Yuval Ronen, reported on Wednesday that these extensions steal users’ wallet secrets and credentials. 

The linkage to discover the fake extensions was made through a meticulous effort to discover shared TTPs and infrastructure. This campaign has been active since April 2025 and is still evolving to discover further harmful activities in the browser.

How Was This done

  • The first step in the destructive move was to gain trust through ratings, reviews, branding, and functionality, which makes the extension appear widely adopted and well reviewed.
  • After gaining trust, they used identical names and logos to impersonate the real services with visual similarities to deceive the users.
  • In cases of open source, extensions cloned the real codebase and inserted their own malicious logic, creating extensions that behaved as expected by secretly stealing personal data.

“The extensions extract wallet credentials directly from the targeted websites and exfiltrate them to a remote server controlled by the attacker. During initialization, they also transmit the victim’s external IP address, likely for tracking or targeting purposes,” said Koi Security. 

Surge of Crypto Hacks in 2025

In May 2025, Coinbase Global announced that hackers obtained personal information, putting more than 70,000 customers at risk of attacks and extortion. Many global agencies, such as OFAC and FATF, have addressed various issues related to crypto hacks; however, despite the growing awareness, millions of individuals still fall victim to these crypto kidnappings.  

Risk Mitigation Steps Recommendations by Koi Security

  • Install extensions only from verified publishers
  • Treat browser extensions as full software assets
  • Use an extension that allows and restricts installation to validated extensions only
  • Timely monitoring to detect ownership transfers and other signs of compromise over time.

To defend against the employees who unknowingly downloaded the malicious extensions for Firefox, these steps are to be followed, as recommended by Koi Security researcher, Ronen.

FAQs

How can I protect my crypto wallet from browser hacks?

Use hardware wallets, avoid browser-based storage, and install wallet tools only from official or verified sources.

What are the best ways to secure crypto wallets in 2025?

Enable 2FA, use cold storage, avoid public Wi-Fi, monitor wallet activity, and beware of phishing and fake extensions.

Elena R and Qadir AK

Elena is an expert in technical analysis and risk management in cryptocurrency market. She has 10+year experience in writing - accordingly she is avid journalists with a passion towards researching new insights coming into crypto erena.

Trust with CoinPedia:

CoinPedia has been delivering accurate and timely cryptocurrency and blockchain updates since 2017. All content is created by our expert panel of analysts and journalists, following strict Editorial Guidelines based on E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness). Every article is fact-checked against reputable sources to ensure accuracy, transparency, and reliability. Our review policy guarantees unbiased evaluations when recommending exchanges, platforms, or tools. We strive to provide timely updates about everything crypto & blockchain, right from startups to industry majors.

Investment Disclaimer:

All opinions and insights shared represent the author's own views on current market conditions. Please do your own research before making investment decisions. Neither the writer nor the publication assumes responsibility for your financial choices.

Sponsored and Advertisements:

Sponsored content and affiliate links may appear on our site. Advertisements are marked clearly, and our editorial content remains entirely independent from our ad partners.

Recent Posts

Ripple XRP Price Prediction 2026, 2027-2030: Will XRP Reach $5?

XRP price currently stands at $2.99, with a market capitalization of $179.79 billion. Analysts and…

February 7, 2026

Bitcoin Price Prediction 2026, 2027 – 2030: How High Will BTC Price Go?

Story Highlights Bitcoin is currently trading at: Predictions suggest BTC to hit $150K to $250K…

February 7, 2026

Cardano Price Prediction 2026, 2027 – 2030: Will ADA Price Hit $2?

Story Highlights The live price of the Cardano token is . Price prediction suggests potential…

February 7, 2026

Curve DAO Token (CRV) Price Prediction 2026, 2027-2030: Can CRV Break Its Long-Term Range?

Story Highlights The live price of the CRV token is . Price predictions for 2026…

February 7, 2026

20% Bounce and an ETF Filing: Why ONDO Price is Separating from the Crypto Pack.

ONDO price is hovering around $0.2539, up roughly 20% from its recent $0.2017 low, and…

February 7, 2026

CFTC Confirms National Trust Bank Stablecoins as Approved Payment Tokens

The U.S. Commodity Futures Trading Commission has taken another step toward formalizing stablecoins within the…

February 7, 2026