Cybersecurity experts have uncovered a set of 16 malicious Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys. These extensions disguise themselves as legitimate wallet portals, desktop utilities, and browser tools, but they are programmed to intercept sensitive information during the wallet import process. The stolen data is then sent to attacker-controlled Cloudflare Workers, according to research by Joseph Edwards from Socket. Most of these extensions mimic either Rabby Wallet or OKX Wallet, with many contacting a specific domain to exfiltrate data. This activity is part of a broader campaign documented earlier this year, where threat actors frequently change package names, versions, and other identifiers to evade detection, while maintaining consistent credential-handling and network strategies. Fortunately, as of early October, all harmful extensions have been removed from circulation. However, users who interacted with these fake wallet platforms should consider their assets compromised. It is critical for them to create new wallets on clean systems and transfer their holdings immediately. This incident highlights a growing trend of malicious extensions affecting major browsers, including Chrome and Edge. To mitigate such risks, users and organizations are urged to regularly review and manage their browser extensions. Removing unnecessary add-ons and implementing runtime and behavior-based monitoring can significantly reduce exposure to these types of threats.