- Socket found 16 Firefox extensions that cloned Rabby and OKX wallets and send recovery phrases and private keys to operator-run Cloudflare Workers.
- Every manifest declared that it collects no data. That label is written by the publisher, so it proves nothing on its own.
- Inventory extensions on managed browsers. Socket advises treating any wallet secret entered into these extensions as exposed, because a new extension password does not change that.
Every one of these 16 Firefox extensions told the browser it collects no data. Socket found code inside them that handles wallet recovery phrases and sends them to outside servers. That gap is the real story. A privacy label is a statement by the publisher, not a check by anyone else.
What Socket found
Socket's researchers traced 16 Firefox add-ons to one operation aimed at people who hold crypto wallets. The names, versions and IDs changed from one add-on to the next. The wallet screens, credential-handling code and campaign marker stayed the same.
On the surface they wore several disguises. Some posed as a generic wallet front end, and others as everyday utility tools.
When a user imports a wallet, the code copies the recovery phrase or private key. It then tries to send that secret to servers the operators run on Cloudflare's Workers service.
A recovery phrase is 12 or 24 words that give full control of a wallet. A private key does the same job. Whoever holds either can move the funds.
Four of the extensions are clones of Rabby Wallet. Twelve are clones of OKX Wallet. Socket says Mozilla unpublished them as of October 5.
How the code works
The operators did not build a fake wallet from scratch. The four Rabby clones are repackaged copies of the real application, each with 1,114 files. The wallet still works. The operators added a second path for the secret.
In the background script, the code installs a small function. It is called right after normal import steps, such as when a seed phrase or private key is entered. The wallet gets the secret it needs. So does the operator's server.
The Rabby clones put the phrase in a web address query string. Socket notes this exposes the secret to request logs and any system that records URLs. The OKX-style clones send it as a JSON body over HTTPS POST.
A comment in one script said only a hash and a word count leave the device. The code sent the phrase itself. Socket calls that contradiction direct evidence of concealment.
The Rabby-clone manifests also asked to run a script on every page, in all frames, including local files. Socket says that is more access than the observed behavior needs. Its static analysis found no separate form-grabber claim, so it describes the risk as excessive access. Socket documents the sending of wallet secrets entered during import.
Why the copy is hard to spot
The clones lean on real brands. The Rabby copy kept links to Rabby's official store listing and legal pages. The OKX-style copy kept OKX interface parts and help links. A user who checks the destination sees a real address.
The tells are small. The Rabby clone is renamed 'Raabby WaIIet'. Package names, versions and IDs rotate while the payload code stays fixed. Socket says this points to a builder pipeline producing variants.
That figure describes the real wallet on a different store. The report gives no install counts for the malicious extensions. It also says one OKX-style variant is broken as shipped, because its manifest never loads the script. Socket calls that a delivery defect, not evidence of good intent.
The lesson: a declaration is not a control
Firefox extensions declare their data collection in the manifest. All 16 declared 'none', next to code that handles recovery phrases. This shows why a store label cannot stand in for your own checks. It is a claim, and claims can be copied as easily as logos.
The exposure reaches beyond hobbyists. Anyone who handles company crypto, or who uses a work browser for personal wallets, could be affected. The documented scope is narrow: wallet secrets entered during import. The financial effect for an affected wallet can still be large.
What to ask your team
Socket's advice for anyone who entered a real phrase or key into one of these extensions is plain. Treat the wallet as exposed. Create a new wallet from a clean device, move assets, and revoke token approvals. Changing the extension password does not invalidate the phrase.
For security teams, Socket suggests several steps. Block the listed extension IDs and file hashes. Search extension inventories for the campaign marker EQOx7EIPZSNi. Search proxy and DNS logs for the Worker namespaces. Keep the secret field, named w, out of case notes and alerts.
Three questions are worth asking this week. Can we list every browser extension on managed devices? Who approves new ones? Does anyone treat a 'no data collected' label as proof?
A label tells you what the publisher wants you to believe. Only inspection tells you what the code does.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Socket.





