Tendvane

← All articles

SecurityOctober 8, 2026

Sixteen Firefox add-ons were copies of real wallets, down to the deliberate typo

One of them called itself Raabby WaIIet. Two capital i's where the l's should be, an extra a in the first word, and otherwise a perfect copy of a wallet that nearly a million people use.

Joseph Edwards at Socket found sixteen of these on Mozilla's add-ons site: four cloning Rabby, twelve cloning OKX. They were not crude fakes. The attackers took the genuine extension's entire codebase and added a few lines to the import function, so when you pasted in a twelve or twenty-four word recovery phrase, or a 64-character private key, it was copied out to a Cloudflare Workers address the attackers controlled before the wallet carried on setting itself up exactly as expected. Nothing broke. Nothing warned you. All sixteen declared in their manifests that they collected no user data. Mozilla had removed the lot by 5 October.

Most people reading this do not have a crypto wallet, and the specific trick here only pays off if you do. The part worth taking away is the delivery route. A browser extension sees everything you type into a page, and almost nobody goes back through the ones they installed two years ago for a coupon finder or a dark-mode toggle. Open your browser's extensions page this week and remove anything you cannot explain. If you did type a real recovery phrase into one of these, treat that wallet as gone: make a new one on a clean machine and move what is left.

Tendvane's safety check sweeps the PC for software that arrived without a clear invitation, and the browser hijacked repair wizard covers the clean-up when something has settled into Firefox or Chrome and will not leave quietly.

Sources

Download Tendvane