0x06821ed80682…06821edb
Sixteen Fake Firefox Wallet Extensions Target Crypto Users
Sixteen counterfeit wallet extensions on the Firefox Add-ons store harvested crypto credentials in a campaign tracked as DarkSword, researchers at shattered.io report.
Outputs
Sixteen fake wallet extensions were listed on the Firefox Add-ons store
The credential-theft campaign has been tracked under the name DarkSword
The fakes impersonated established wallet brands to capture seed phrases and login data
Security researchers at shattered.io documented the activity in a 2026 report
Sixteen counterfeit cryptocurrency wallet extensions listed on the Firefox Add-ons store have been caught harvesting credentials from crypto users, according to a report by security researchers at shattered.io covering 2026 activity.
The fraudulent add-ons impersonated well-known wallet brands, presenting themselves as legitimate tools for managing browser-based crypto holdings. Once installed, the fakes were positioned to capture seed phrases, private keys and exchange login data typed or stored by victims. The campaign has been tracked under the name "DarkSword," which researchers attached to this wave of malicious Firefox listings.
How did the fake extensions reach users?
Attackers relied on typosquatting and lookalike branding rather than exploiting Firefox itself. The sixteen extensions mirrored the names, icons and descriptions of recognizable wallet products, a tactic that has repeatedly proven effective on browser storefronts where review processes are less rigorous than mobile app stores.
Users searching for a wallet extension could land on a counterfeit listing instead of the genuine developer's page. Install counts, spoofed reviews and polished store descriptions lent the fakes an air of legitimacy. The attack required no zero-day vulnerability: the delivery mechanism was the add-on store itself, and the payload ran with the permissions users routinely grant wallet extensions.
What is DarkSword?
DarkSword is the name researchers gave to this cluster of malicious activity. The campaign centers on credential theft aimed directly at self-custodied funds. A wallet extension that can read page content and intercept form inputs can capture a seed phrase at the moment a user types or pastes it, or exfiltrate credentials for exchange accounts.
Because transactions on chains like Ethereum and Bitcoin are irreversible, a captured seed phrase typically means total loss of the associated funds. Victims have no chargeback path and, in most jurisdictions, limited practical recourse.
Why do browser stores keep hosting wallet malware?
This is not the first such incident, and the pattern explains why wallet fakes recur across storefronts. Genuine wallet extensions handle secrets by design, so users have been conditioned to enter high-value credentials into add-ons. That makes impersonation attacks unusually efficient: the malicious version only needs to look identical, not function identically.
Store operators have responded in past waves with takedowns and tightened review requirements, but listings typically remain live until reported. The gap between publication and removal is the window in which these campaigns operate.
What should users do now?
Practical defenses are limited but concrete:
- Verify the developer's official website links directly to the store listing before installing
- Treat any wallet extension requesting broad page-reading permissions with suspicion
- Use hardware wallets for significant holdings, keeping seed phrases off browser environments entirely
- Report suspected fakes to Mozilla so listings can be pulled
Mozilla has historically removed reported malicious add-ons within days, but enforcement remains reactive rather than preventive. Until storefront review processes verify wallet-extension publishers before publication, lookalike listings will continue to surface, and users who self-custody should assume the burden of verification rests with them.
via Google News - Crypto Hack Exploit (Source)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles