GreedyBear Strikes: Malicious Extensions Drain $1M in Crypto Theft Fiasco
GreedyBear is on a roll, using over 150 malicious Firefox extensions to steal $1 million in crypto. Masquerading as popular wallets, these sneaky add-ons exploit user trust with a technique called Extension Hollowing. It’s the digital equivalent of a Trojan horse, but instead of Greeks, it’s after your digital gold.

Hot Take:
Who knew that the crypto world had its own version of Ocean’s Eleven? Only this time, it’s starring GreedyBear and his 150 Firefox accomplices! Watch out, because these digital bandits are using “Extension Hollowing” to sneak past your defenses and make off with your precious crypto. It’s a heist even Danny Ocean would envy!
Key Points:
- GreedyBear campaign uses over 150 malicious Firefox extensions to steal over $1 million.
- Employs “Extension Hollowing” to bypass Mozilla’s security reviews.
- Fake extensions impersonate popular crypto wallets like MetaMask and TronLink.
- Campaign linked to a single threat actor using a common C2 server.
- AI tools and aged YouTube accounts aid in the campaign’s execution.
Already a member? Log in here