📈 Get daily crypto insights that make you smarter about your money

GreedyBear Campaign Drains $1M+ Through 150 Malicious Firefox Crypto Wallet Extensions

The cryptocurrency community faces a growing threat from sophisticated browser extension attacks, as a widespread campaign dubbed “GreedyBear” has stolen more than $1 million in digital assets through over 150 malicious Firefox extensions. The campaign, first reported in early August 2025, exploits a fundamental trust mechanism: users’ reliance on official browser marketplaces as safe sources for software.

The Exploit Mechanics

The attackers behind GreedyBear employ a technique known as “Extension Hollowing” to circumvent Mozilla’s security review process. The operation begins with the submission of an innocuous, empty extension to the Firefox Add-on Store. Once approved and listed, the attackers cultivate a veneer of credibility by generating fake positive reviews. After building sufficient trust, they remotely update the extension to inject malicious code. This approach effectively weaponizes the marketplace’s own trust infrastructure against its users.

The malicious extensions were designed to impersonate popular cryptocurrency wallets such as MetaMask and Coinbase Wallet. When an unsuspecting user installed one of these fraudulent extensions and attempted to log into their actual wallet, the malicious code would capture their credentials and seed phrases in real time. This sensitive data was then exfiltrated to attacker-controlled servers, giving criminals full access to victims’ cryptocurrency holdings.

Security researchers believe the GreedyBear campaign represents an evolution of the earlier “Foxy Wallet” operation, suggesting a highly organized criminal enterprise that has been refining its techniques over multiple iterations. The scale of the operation, with more than 150 extensions deployed across the marketplace, indicates significant resources and coordination.

Affected Systems

The primary targets of this campaign are Firefox browser users who actively manage cryptocurrency holdings through browser-based wallet extensions. Given Bitcoin’s price of approximately $118,731 and Ethereum trading around $4,227 in mid-August 2025, even a single compromised wallet can represent substantial financial losses. The campaign specifically targeted users of MetaMask and Coinbase Wallet, two of the most widely used browser-based cryptocurrency wallets in the ecosystem.

Beyond individual users, the attack has implications for decentralized application developers who rely on browser extensions as the primary interface between users and their platforms. The vulnerability exposed by GreedyBear challenges the assumption that official marketplaces provide adequate security screening for financial applications.

The Mitigation Strategy

For users who may have installed suspicious wallet extensions, immediate action is required. Remove any recently installed wallet extensions from Firefox and verify that you downloaded the authentic version directly from the wallet provider’s official website. Change all seed phrases and migrate funds to new wallet addresses if there is any doubt about the integrity of your current setup.

Mozilla has since purged the malicious extensions from its marketplace and is implementing enhanced review processes for extensions that request sensitive permissions. However, the incident highlights the need for a fundamental shift in how users interact with browser-based crypto tools.

Lessons Learned

The GreedyBear campaign demonstrates that attackers are increasingly targeting the human layer of the crypto security stack rather than technical vulnerabilities in blockchain protocols. The reliance on browser extensions as the primary intermediary between users and decentralized applications creates a significant attack surface that bad actors are eager to exploit.

Several key principles emerge from this incident. First, official marketplaces are not infallible security guarantees. Second, the use of hardware wallets for storing significant cryptocurrency holdings remains the gold standard for protection against credential theft. Third, the industry needs to develop more secure standards for connecting decentralized applications to user wallets, reducing dependence on browser extensions as the primary gateway.

User Action Required

If you use Firefox and have installed any cryptocurrency wallet extension in recent weeks, take the following steps immediately: verify the extension’s publisher through the official wallet website, check for any unusual login activity, and consider migrating to a hardware wallet for long-term storage. With Bitcoin hovering near $118,700 and Ethereum above $4,200, the stakes are too high to rely solely on browser-based security. Stay vigilant, verify sources independently, and never enter seed phrases into browser extensions without confirming their authenticity through multiple channels.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research before making decisions about cryptocurrency security.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “GreedyBear Campaign Drains $1M+ Through 150 Malicious Firefox Crypto Wallet Extensions”

  1. submitting an empty extension then injecting malicious code post-approval is such a clean exploit of the review process. mozilla needs continuous scanning not just initial vetting

    1. addon_audit_ staged rollouts would catch this too. pushing updates to 1pct of users first and monitoring for anomalies is standard practice everywhere except browser extensions apparently

  2. Mozilla_refugee_

    150 malicious extensions and Mozilla only caught it after 1M was gone. the chrome web store has the same problem, browser extension security is a decade behind

    1. Katrin Muller

      Yuki Tanaka the best projects during bear markets include security tools. GreedyBear exposed a fundamental flaw in extension trust models

  3. 150 extensions and $1M later. google chrome store has the same problem but nobody talks about it because the chrome team is busy shipping gemini features

  4. fake 5-star reviews on malicious metamask clones is such a basic social engineering trick. 150 extensions before anyone noticed is embarrassing for mozilla

    1. Sigrid N. fake reviews on the firefox addon page. you can buy 50 five star reviews for $200 on telegram. the trust model is completely broken

      1. Margot F. you can buy 50 fake five star reviews for pocket change on telegram. the addon store trust model is completely cooked

  5. 150 malicious extensions and the attack vector was updating benign extensions after approval. the review process needs continuous monitoring not just initial screening

    1. ext_hunter_ mozilla switched to a one-click install model that skips review for updates. the hollowing trick works because the initial submit is clean

    2. ext_hunter_ submitting empty extensions then injecting malicious code post-approval breaks the entire addon trust model. mozilla needs continuous scanning not just initial review

    3. csp_enforcer_

      Mozilla rolled out staged rollouts for updates after this. extension hollowing would not have worked if reviewers checked what changed between versions

      1. csp_enforcer_ staged rollouts help but the real fix is signed update diffs. if the addon store compared the initial hash against the updated code this attack dies instantly

  6. manifest_v3_rat

    extension hollowing works because Mozilla reviews the initial submission then allows remote updates without re-review. the chrome web store has the same gap

    1. manifest_v3_rat Mozilla switched to one-click install for updates specifically to reduce friction. they traded security for UX and GreedyBear exploited exactly that

  7. 150 extensions and only $1M stolen. thats about $6.6k per extension. these were low-skill attackers targeting very small wallets. imagine what organized groups could do

    1. seed_drift_ $6.6k per extension is actually smart from the attacker side. stay small, avoid big targets, fly under the radar. 150 small drains add up without triggering KYC alerts or exchange freezes

  8. the mozilla addon review process being reactive instead of proactive is the real story here. they wait for reports then take action. by then the seed phrases are already gone

  9. Extension Hollowing is such a clean name for it. submit empty, get approved, push malicious update. Mozilla review process is a revolving door

  10. 150 extensions stealing seed phrases and Mozilla only caught it after 1M gone. switch to hardware wallet signing and none of this matters

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$76,731.00-0.6%ETH$2,477.46-1.8%SOL$99.92-1.7%BNB$715.71-1.4%XRP$1.34-1.8%ADA$0.2028-1.9%DOGE$0.0824-2.7%DOT$0.9996-1.8%AVAX$7.30-1.1%LINK$11.19-2.6%UNI$6.15-3.2%ATOM$1.58-1.7%LTC$53.63+0.2%ARB$0.1331-4.9%NEAR$2.31-1.8%FIL$0.9427+18.0%SUI$0.7011-2.9%BTC$76,731.00-0.6%ETH$2,477.46-1.8%SOL$99.92-1.7%BNB$715.71-1.4%XRP$1.34-1.8%ADA$0.2028-1.9%DOGE$0.0824-2.7%DOT$0.9996-1.8%AVAX$7.30-1.1%LINK$11.19-2.6%UNI$6.15-3.2%ATOM$1.58-1.7%LTC$53.63+0.2%ARB$0.1331-4.9%NEAR$2.31-1.8%FIL$0.9427+18.0%SUI$0.7011-2.9%
Scroll to Top