Security firm Socket identified 40 Firefox extensions with confirmed malicious behavior, including nine that transitioned from sports-score tools to crypto-targeting software. These add-ons exposed recovery phrases, private keys, and serialized wallet keyrings, permanently compromising affected wallets even after uninstallation. Mozilla removed one active phishing extension, but the number of victims, involved transactions, and total loss amount remain unknown. Users whose secrets were exposed must migrate their assets to a fresh wallet created from a new recovery phrase.
Source: Read the original article

