• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Thursday, June 11, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Crypto

Surging “FoxyWallet” Scams: How Fake Crypto Wallet Add-ons Are Lurking in Firefox

by Anindya Paul
July 4, 2025
in Crypto
Reading Time: 4 mins read
0
FoxyWallet

Source: Mozilla

TwitterWhatsappLinkedin

Since April 2025, a growing series of false cryptocurrency wallet extensions, collectively called “FoxyWallet”, have made their way into the Firefox Add on store. Appearing as well-known brands like MetaMask, Coinbase, Trust Wallet, and Phantom, these impostors use cloned open source code with malicious payloads. As a result, users’ seed phrases and private keys are captured and siphoned away by attackers, probably a Russian speaking threat group, allowing them to drain crypto assets from there on out.

You might also like

High Stakes on the Senate Floor: Could Stablecoins Drain 35% of U.S. Bank Deposits?

Wall Street Meets Web3: Trad.Fi and W3 Partner for a $650 Million AI-Powered Private Credit Revolution

Major Security Breach at Humanity Protocol: Employee Laptop Hack Leads to $36 Million Loss

A Coordinated Scam Since April

Koi Security has linked over 40 fake wallet extensions to this campaign, noting that new versions appear almost weekly. These impersonators provide users with the expected wallet interface to distract them from submitting sensitive inputs—such as seed phrases longer than typically longer than 30 characters—and then used to transmit the phrase with the user’s IP to attackers server.

How Trust Is Fabricated

The scam employs a variety of means to create false legitimacy:

  • Identical branding: they use legitimate names, and logos from genuine wallets.
  • Fake five star reviews: Inflated review counts far exceed real installation figures, misleading users.
  • Open source tactics: The clones maintain normal functionality but embed malicious code—a low effort, high impact strategy.

As a result, users reviewing the browser interface see what appears to be a safe, well rated extension, unaware that a silent attacker is harvesting credentials.

Who’s Behind the Mask?

Malware analysis showed comments in Russian, and a command and control PDF with metadata suggests links to Russian speaking group. Attribution is still preliminary, however, the multilingual footprint suggests a potentially more coordinated effort.

Mozilla’s Defensive Steps

Mozilla implemented a new “early detection” defense on June 3, assigning risk profiles to add ons and flagging suspicious submissions for human review. That measure has led to the removal of many offending extensions, yet at least seven still linger in the store as of early July.
A Mozilla spokesperson confirmed that the company continues to refine its systems and pull down malicious extensions swiftly once identified.

Broader Implications: Beyond Browser Scams

The FoxyWallet scandal is just one facet of a broader crypto fraud landscape. Hardware wallet scams, fake Ledger Live clones, and physical phishing campaigns—like USPS sent QR code letters—are also emerging threats. In the first half of 2025 alone, wallet breaches have yielded more than $1.7 billion in losses.

Staying Safe: Practical Advice

Bundled Apps: Extensions, add-ons, or apps are often bundled with software that you are installing. Caution should be practiced because you may be installing other potentially unwanted software.
To protect yourself from these threats, experts suggest:

  • Check publisher identity: Download from the published wallet website and not a search engine.
  • Monitoring ratings and install counts: Are there high ratings and not many installs? The difference in rating and installs can be very misleading.
  • Vet open source clones very carefully: A legitimate extension being a clone is not a guarantee-it must come from verifiable sources.
  • Treat extensions as critical software assets: Apply policies, allowlists, and ongoing scrutiny to browser extensions—just like apps on your phone or desktop.

Final Word

The FoxyWallet embers of extortion provide a strong reminder that even trusted platforms like Firefox can be compromised. The convenience offered by browser crypto access comes with inherent risk and once an attacker obtains your seed phrase, there is nearly no way to reverse the situation. Although vigilance rewarded by verifiable sources with cautious extension use is your greatest defense in a hacked world where cybercriminals can easily mimic legitimacy.

Tweet60SendShare17
Previous Post

How to cancel your Gold Gym membership?

Next Post

U.S. Lawmakers Set National Blockchain Strategy in Motion

Anindya Paul

Professional content creator with strong expertise in content writing, filmmaking and social media strategy. Skilled in digital storytelling, scriptwriting, video production, sound design and graphic design - crafting compelling narratives across platforms. Known for delivering high-quality, engaging content under tight deadlines. A collaborative team player with a sharp creative instinct, adaptability to evolving trends, and a focus on impactful, results-driven communication.

Recommended For You

High Stakes on the Senate Floor: Could Stablecoins Drain 35% of U.S. Bank Deposits?

by Anindya Paul
June 11, 2026
0
CLARITY Act

The much valued CLARITY Act is on the Senate floor for discussion with many different angles being reviewed regarding the ability of stablecoin issuers to offer yield on...

Read more

Wall Street Meets Web3: Trad.Fi and W3 Partner for a $650 Million AI-Powered Private Credit Revolution

by Anindya Paul
June 11, 2026
0
Trad.Fi

A seismic shift is taking place in the world of commercial finance through advancements in technology. Trad.Fi, a long-time supplier of equipment finance has partnered with W3 to...

Read more

Major Security Breach at Humanity Protocol: Employee Laptop Hack Leads to $36 Million Loss

by Anindya Paul
June 11, 2026
0
Humanity Protocol

The cryptocurrency community has borne the brunt of a devastating security breach. Recently, Humanity Protocol (a decentralized identity initiative utilizing palm-based proof of humanity technology) acknowledged that an...

Read more
Next Post
U.S.

U.S. Lawmakers Set National Blockchain Strategy in Motion

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?