Market Cap: $2.6616T 2.09%
Volume(24h): $78.8372B -10.97%
  • Market Cap: $2.6616T 2.09%
  • Volume(24h): $78.8372B -10.97%
  • Fear & Greed Index:
  • Market Cap: $2.6616T 2.09%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$77560.422694 USD

1.38%

ethereum
ethereum

$2487.453153 USD

1.65%

tether
tether

$0.999055 USD

0.00%

bnb
bnb

$754.929766 USD

3.97%

xrp
xrp

$1.325914 USD

1.70%

usd-coin
usd-coin

$0.999829 USD

-0.01%

solana
solana

$105.756375 USD

5.69%

tron
tron

$0.335859 USD

0.15%

zcash
zcash

$1491.934575 USD

9.81%

hyperliquid
hyperliquid

$87.784577 USD

10.62%

dogecoin
dogecoin

$0.084281 USD

3.81%

monero
monero

$531.066198 USD

7.27%

chainlink
chainlink

$11.802944 USD

5.34%

unus-sed-leo
unus-sed-leo

$8.892769 USD

-0.44%

cardano
cardano

$0.213660 USD

7.72%

Cryptocurrency News Articles

GreedyBear's Crypto Heist: Russian Hackers, Firefox Extensions, and a Million-Dollar Crypto Theft

Aug 10, 2025 at 11:50 pm

A Russian-linked group, GreedyBear, stole over $1 million in crypto by weaponizing Firefox extensions. Learn how they did it and how to stay safe!

GreedyBear's Crypto Heist: Russian Hackers, Firefox Extensions, and a Million-Dollar Crypto Theft

Hold on to your hats, crypto enthusiasts! A Russian-linked cybercriminal group named GreedyBear has been wreaking havoc, pilfering over $1 million in cryptocurrency in just five weeks. Their weapon of choice? Weaponized Firefox extensions. Buckle up, because this is a wild ride.

GreedyBear's Extension Hollowing Tactic

GreedyBear didn't just stumble into this million-dollar heist. They strategically deployed 150 malicious Firefox extensions, primarily targeting English-speaking crypto users. Koi Security reports they nearly tripled their attack arsenal since April 2025. How did they do it?

They used a sneaky method called “Extension Hollowing.” GreedyBear uploads legitimate versions of popular crypto wallet extensions—think MetaMask, Exodus, Rabby Wallet, and TronLink—and then updates them with malicious code. This lets them bypass Firefox's security checks and stay hidden for ages. Crafty, right?

Once installed, these extensions swipe sensitive wallet credentials, giving GreedyBear access to drain crypto assets. They even fabricate positive reviews to trick users. Talk about a comprehensive con!

Beyond Firefox: A Multi-Pronged Attack

But wait, there's more! GreedyBear also distributed nearly 500 malicious Windows executables on Russian software platforms. These include credential stealers, ransomware, and trojans, often bundled with pirated software. And if that's not enough, they run dozens of phishing websites mimicking legitimate crypto services, snagging login credentials and siphoning funds.

Most of these attacks trace back to a single IP address—185.208.156.66—suggesting a centralized operation. This structured approach indicates a growing sophistication and operational scale.

Staying Safe in the Crypto Wild West

This campaign highlights the growing risks in the crypto world. As we rely more on browser extensions and software to manage digital assets, we become bigger targets. So, how do we stay safe?

  • Verify Everything: Only download extensions and software from trusted sources.
  • Enable Multi-Factor Authentication: Add an extra layer of security to your accounts.
  • Regular Updates: Keep your applications updated to patch vulnerabilities.

The Browser Battle: What's Next?

This attack is a wake-up call for browser companies like Mozilla. They need to step up their game, improving how they check and monitor extensions, especially after installation. Extension Hollowing is a sneaky trick that needs to be addressed ASAP.

AI's Role in Cybercrime

Cybersecurity experts suggest that artificial intelligence tools are contributing to the speed and complexity of campaigns like GreedyBear's. AI likely enhances their ability to evade detection and rapidly iterate on new attack methods. As this operation evolves, analysts warn that similar campaigns may soon emerge on other major browsers, including Chrome and Edge.

Final Thoughts: A Crypto Caper

So, what’s the takeaway? The world of crypto is a bit like the Wild West, but with more lines of code and fewer tumbleweeds. Stay vigilant, double-check those extensions, and maybe keep your digital wallet a little closer. After all, a little paranoia never hurt anyone—especially when Russian hackers are on the prowl. Happy (and safe) trading, folks!

Original source:ainvest

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 19, 2026