Two separate crypto wallet seed phrase theft campaigns surfaced within 72 hours of each other in early October 2026, and together they show how far attackers have moved beyond the classic phishing email. Socket Threat Research disclosed 16 malicious Firefox extensions on October 7 that cloned the interfaces of Rabby Wallet and OKX Wallet to capture 12-word and 24-word recovery phrases. One day later, researchers at Censys published findings on a separate operation called DarkSword and its companion malware Coruna, an iOS exploitation platform that had already harvested recovery phrases directly from compromised iPhones.

Neither campaign stole from an exchange or a smart contract. Both went straight for the one secret that nothing else can substitute: the seed phrase that recreates a wallet’s private keys. That distinction matters for anyone who has spent 2026 reading headlines about nine-figure exchange breaches and DeFi exploits, because it points to where the next wave of losses is likely to come from.

A Rough Week for Crypto Wallet Seed Phrase Security

Security researchers have tracked a steady shift in how criminals go after cryptocurrency. Rather than attack a blockchain’s cryptography directly, which is still computationally out of reach, attackers target the software and hardware layer where a human has to type, store, or move a seed phrase. The Firefox extension cluster and the DarkSword/Coruna platform both sit in that category, and both surfaced in the same week, which is why security teams are treating them as a single story rather than two unrelated incidents.

The timing lands during what has already been a brutal year for crypto wallet seed phrase theft and wallet security broadly. Chainalysis put total 2025 crypto theft at roughly $3.4 billion, with $713 million of that coming specifically from personal wallet compromises such as seed phrases typed into fake sites, wallet-draining malware, and malicious browser extensions, a trend our earlier wallet security breakdown covered in detail. September 2026 alone saw PeckShield tally $766 million in crypto hack losses across exchanges, bridges, and protocols, a 462% jump from August. The Firefox and DarkSword campaigns show that even as exchange-level hacks grab the bigger dollar figures, the quieter theft of individual wallets keeps running in parallel.

Inside the 16 Malicious Firefox Extensions

Socket’s research team, led by analyst Joseph Edwards, found that the 16 extensions did not present themselves as wallets from the moment a user installed them. Instead they launched as ordinary browser utilities, desktop helper tools, or wallet “portals,” a staging approach that let them sit in Mozilla’s add-on store without immediately tripping automated review filters. Only later, once a user tried to import an existing wallet, did the extensions switch to a cloned interface.

Four of the 16 extensions directly impersonated Rabby Wallet, a multi-chain wallet popular with DeFi users, while the remaining group mimicked OKX Wallet’s import flow. Both are real, widely used products, which made the counterfeit screens convincing enough to fool users who were not checking the extension’s publisher or review history closely.

How the Fake Wallet Screens Captured Secrets

Once a victim reached the fake import screen, the extension’s code accepted two very specific input formats: a 12-word or 24-word BIP39 recovery phrase, or a raw 64-character hexadecimal private key. That is not a coincidence. Those are the only two formats a legitimate wallet ever asks for during an import, so building detection around exactly those shapes let the malware stay quiet during normal browsing and only activate at the one moment it mattered.

Socket’s writeup pointed to an injected helper function buried in each extension’s background script, referenced internally as self._lv, which scanned text input for phrase-shaped or key-shaped strings before forwarding anything that matched. Below is a simplified version of the pattern researchers described, shown only to illustrate how narrowly the check was built, not as working exploit code.

function isSeedOrKey(input) {
  const words = input.trim().split(/\s+/);
  const isSeedPhrase = words.length === 12 || words.length === 24;
  const isHexKey = /^[0-9a-fA-F]{64}$/.test(input.trim());
  return isSeedPhrase || isHexKey;
}
// background.js matched input, then relayed it to a remote endpoint

Whatever the extension captured was routed to attacker-controlled infrastructure built on Cloudflare Workers, a serverless platform that is cheap to spin up and blends in with a huge volume of legitimate web traffic. That choice of infrastructure is a recurring theme in 2026 wallet-drainer cases, since Cloudflare’s own edge network makes it hard for defenders to distinguish malicious traffic from the millions of benign requests passing through the same service every second.

Mozilla’s Takedown, and Why It Was Not Enough

Mozilla had already pulled all 16 extensions from its add-on marketplace by October 5, 2026, two days before Socket’s public writeup went live. That is a reasonably fast turnaround once a campaign is flagged, and it stopped new installations cold. But a takedown only closes the front door. Anyone who had already typed a real seed phrase or private key into one of the fake import screens was still compromised the moment they hit submit, regardless of when Mozilla acted afterward.

Socket’s guidance for affected users was blunt: treat any wallet whose phrase was entered into one of the 16 extensions as burned. The only safe move is to generate a brand-new wallet on a clean device and move remaining funds immediately, the same advice our seed phrase backup guide gives for any suspected exposure. Removing the extension does nothing to protect funds that were already exposed, since the theft happens the instant the phrase is submitted, not continuously while the extension stays installed.

DarkSword and Coruna: A Second Front on iPhones

While Socket was tracking the Firefox cluster, researchers at Censys were separately mapping exposed infrastructure tied to a platform called DarkSword. Censys found open directories on the operator’s servers between September 15 and September 17, 2026, and the picture that emerged was closer to a commercial exploitation service than a single hacking crew. DarkSword appears designed to compromise iPhones directly, while a companion payload called Coruna handles the harvesting once a device is accessible.

Coruna’s job is narrow and specific: search a compromised device’s storage, including the Photos and Notes apps, for text that passes a BIP39 checksum, the same validation step a legitimate wallet uses to confirm a recovery phrase is well-formed. That detail matters because plenty of people who would never type a seed phrase into a sketchy website still keep a screenshot or a Notes entry of it as a backup, assuming the phone itself is safe. DarkSword’s design treats that assumption as the vulnerability.

What Censys Found Inside the Operator’s Infrastructure

One captured production environment contained 11 stolen BIP39 recovery phrases alongside 179 separate device loot directories, the storage folders where harvested data from individual compromised phones gets dropped. Researchers also identified more than 75 operator or control-plane accounts and at least 18 wallet-specific theft modules built into the platform, with the captured phrases tied to six different wallet brands. That module count suggests DarkSword’s operators built it to work against a broad slice of the wallet market rather than a single target app.

No confirmed dollar total for DarkSword/Coruna losses has been published yet, and the available reporting does not establish how the initial iPhone compromise happens in each case. What is established is the scale of the exposed back end: 179 loot directories implies substantially more victims than the 11 recovered phrases alone would suggest, since not every stolen file on a compromised device will turn out to be a valid seed phrase.

Comparing the Two Campaigns Side by Side

Despite surfacing in the same week and sharing the same end goal, the Firefox cluster and DarkSword/Coruna are built on almost opposite methods. One relies on social engineering and a convincing fake interface, the other on exploiting the device itself. The table below lays out how they compare.

Attribute16 Firefox ExtensionsDarkSword / Coruna
Discovered bySocket Threat ResearchCensys
Disclosure dateOctober 7, 2026October 8, 2026
Platform targetedDesktop Firefox browserApple iPhone (iOS)
Entry methodFake wallet-import screens in cloned extensionsiOS exploitation, then on-device data harvesting
Wallets impersonatedRabby Wallet, OKX WalletSix wallet brands (not fully named in public reporting)
Data captured12/24-word phrases, 64-char hex private keysBIP39 phrases found in Photos, Notes, and other files
Exfiltration infrastructureCloudflare Workers endpointsOperator-controlled command-and-control servers
Scale confirmed so far16 extensions, victim count unverified11 recovered phrases, 179 device loot directories, 75+ operator accounts
Response action takenMozilla unpublished all 16 by October 5, 2026Infrastructure exposed publicly, no confirmed takedown reported yet

2026’s Pattern of Seed Phrase and Wallet Attacks

These two October campaigns did not appear out of nowhere. They extend a pattern that has run through the entire year, where the weakest point in crypto custody keeps turning out to be the moment a human has to handle a seed phrase, not the cryptography protecting the wallet itself. Our coverage of the Coldcard firmware flaw from earlier this year showed a five-year-old randomness bug, detailed in Coinkite’s own security advisory, drain roughly $116 million from more than 5,000 addresses. Trezor’s email breach separately exposed 347,000 addresses to follow-up phishing calls aimed at getting owners to hand over their recovery phrases directly.

The table below places the Firefox and DarkSword campaigns alongside other notable 2025 and 2026 seed-phrase and wallet-security incidents, drawing on figures from Chainalysis, PeckShield, and Scam Sniffer where those firms have published numbers.

IncidentTimeframeReported ScaleSource
Wallet-drainer losses, full year2025$83.85 million across 106,106 victims (down 83% from $494M in 2024)Scam Sniffer
Personal wallet compromises, full year2025$713 million of $3.4B total crypto theftChainalysis 2026 Crypto Crime Report
Coldcard firmware RNG flawJuly 2026Roughly $116 million drained from 5,000+ addressesCoinkite, industry reporting
Trezor email list breach2026347,000 emails exposed, used for follow-up phishing callsTrezor disclosure
WaterPlum wallet hack (North Korea-linked)2026$10.7 million drained from roughly 7,000 walletsIndustry security research
Crypto hack losses, single monthSeptember 2026$766 million, up 462% from August’s $136.3 millionPeckShield
16 malicious Firefox extensionsOctober 202616 extensions, victim count unverifiedSocket Threat Research
DarkSword / Coruna iOS platformSeptember-October 202611 recovered phrases, 179 device loot directoriesCensys

Read together, the pattern is less about any single exploit and more about volume. Attackers are running dozens of smaller, cheaper campaigns against individual wallet holders at the same time they chase nine-figure exchange breaches, because both approaches pay and neither requires breaking actual encryption.

Why Browser Extensions Keep Working as an Attack Vector

Browser extension stores have struggled with this exact problem for years, and 2026 has not been an exception. Extensions get broad permissions almost by design, since a password manager or a wallet extension genuinely needs to read page content and intercept form inputs to do its job. That same permission set is indistinguishable, from a review system’s point of view, from what a wallet-stealing extension needs to do the same thing maliciously.

The staged-reveal trick used in this campaign, where an extension behaves innocently for a period before switching on its theft logic, is specifically built to beat the kind of automated and manual review that marketplace operators rely on. A reviewer testing the extension on day one sees a harmless utility. A user who installs it weeks later and later tries to import a wallet sees something else entirely. That gap between what gets reviewed and what eventually runs is the core weakness this campaign exploited, and it is not unique to Firefox. Chrome’s Web Store has dealt with versions of the same problem, and any extension marketplace that allows post-publication code updates faces a version of this risk.

The iPhone Problem: Trust in a “Closed” Platform

DarkSword’s targeting of iPhones cuts against a common assumption in the crypto community that Apple’s tighter app review and sandboxing make iOS meaningfully safer for storing sensitive data than an open desktop browser. That assumption is not wrong in general, but it has a specific blind spot: once a device itself is exploited, rather than tricked through a malicious app, the operating system’s app-store protections stop being relevant. DarkSword is described as an exploitation platform precisely because it appears to work around normal app-based restrictions rather than through them.

The deeper issue for individual holders is habit, not platform choice. A screenshot of a seed phrase sitting in Photos, or a Notes entry labeled “wallet backup,” is just as retrievable to an attacker with device access as a phrase typed into a phishing site. Self-custody guidance has pushed people away from cloud password managers and toward on-device storage for years, but on-device storage is only safer if the device itself cannot be remotely harvested, an assumption DarkSword directly undermines.

Market and Industry Impact

Neither campaign has moved cryptocurrency prices, and that is itself notable. Exchange-level breaches like Bitget’s $387.5 million loss in September 2026 tend to generate immediate market reaction because they threaten a specific company’s solvency and customer trust. Seed-phrase theft spread across thousands of individual wallets does not create that same single point of failure, so it rarely shows up in token prices even when the aggregate losses, like the $713 million Chainalysis attributed to personal wallet compromises in 2025, rival a mid-sized exchange hack.

The real impact lands on wallet vendors and browser makers, who absorb reputational damage every time their brand gets cloned convincingly enough to fool users. Rabby and OKX did nothing wrong here, their interfaces were simply good enough targets to copy, but both brands now carry some of the reputational cost of a scam they did not build. Mozilla faces a similar dynamic: a fast takedown is good crisis response, but each new wallet-drainer cluster that gets through initial review chips away at the argument that extension marketplaces are meaningfully curated.

How This Compares to Past Wallet-Drainer Campaigns

Browser-based wallet drainers are not new. What distinguishes the October 2026 Firefox cluster from earlier waves is the staging behavior and the specific choice of Cloudflare Workers for exfiltration, both signs of operators iterating on detection evasion rather than reusing older, more obvious phishing kits. Scam Sniffer’s 2025 numbers, an 83% drop in drainer losses to $83.85 million from $494 million in 2024, suggested the broader drainer ecosystem was shrinking as wallets added better warning prompts and users got more cautious about signing unfamiliar transactions.

This campaign suggests attackers adapted rather than gave up. Instead of tricking users into signing a malicious transaction, which modern wallets increasingly flag with warnings, the Firefox extensions skip the transaction step entirely and go straight for the raw recovery phrase during import, a moment that most wallet security prompts do not cover at all. DarkSword’s device-level harvesting is an even further step back from transaction-based attacks, targeting data at rest rather than any action the user takes in the moment.

What Crypto Holders Should Do Right Now

For anyone holding a meaningful amount of cryptocurrency, the practical response to both campaigns is the same regardless of which platform they use.

  • Never type a seed phrase or private key into a browser extension, even one that looks identical to a wallet you already trust, unless you installed it directly from the vendor’s own official download link.
  • Check installed Firefox extensions against Mozilla’s current add-on list and remove anything unfamiliar or rarely used, since dormant extensions are a common vector for this kind of staged attack.
  • Stop storing seed phrases as screenshots or Notes entries on a phone. Use a dedicated hardware wallet or a properly isolated offline backup instead.
  • If a phrase was ever entered into one of the 16 named extensions, treat that wallet as compromised immediately and move funds to a freshly generated wallet.
  • Keep iOS and all apps updated, since exploitation platforms like DarkSword rely on unpatched vulnerabilities to gain initial device access.

Our reporting on infostealer malware, which was tied to 1.8 billion stolen credentials in 2025, covers the broader malware ecosystem these campaigns belong to, and the overlap between credential-stealing malware and wallet-specific theft modules is likely to keep growing through the rest of 2026.

What Comes Next: Five Predictions

Based on how both campaigns were built and how the broader market has responded to similar incidents, a few trends look likely to play out over the next several months.

  • More browser-extension campaigns will adopt the staged-reveal approach, since it worked well enough here to get past initial marketplace review on two separate wallet brands at once.
  • Mozilla and Chrome will likely tighten review of any extension that requests clipboard or form-input access after it has already been published, closing the specific gap this campaign exploited.
  • Expect at least one more named iOS exploitation platform similar to DarkSword to surface before year-end, given how much infrastructure Censys found already built out and operational.
  • Wallet vendors like Rabby and OKX will likely add stronger in-app warnings during the import flow specifically, since that moment is now a confirmed target rather than a theoretical risk.
  • Aggregate personal wallet compromise losses for 2026 will probably land above the $713 million Chainalysis recorded for 2025, given the pace of incidents already logged through September and October.

None of these are guarantees, and attackers have repeatedly shown they adapt faster than marketplace review processes can patch any single gap. But the shape of both October campaigns points toward more sophisticated social engineering layered on top of simpler technical tricks, rather than any single breakthrough exploit.

Frequently Asked Questions

What were the 16 malicious Firefox extensions actually called?
Socket’s October 7, 2026 report did not publish a full list of extension names in its public summary, since Mozilla had already unpublished all 16 by October 5. Firefox users should check Mozilla’s own add-on removal notices and remove any wallet-related extension they do not clearly recognize installing themselves.

Were Rabby Wallet and OKX Wallet themselves hacked?
No. Both are legitimate products that were impersonated by separate, unrelated browser extensions. Neither company’s actual wallet software or infrastructure was compromised.

How do I know if DarkSword or Coruna affected my iPhone?
There is no public self-check tool for this platform as of this writing. The safest assumption, given that Censys found 179 device loot directories tied to the operation, is to treat any seed phrase ever stored as a screenshot or Notes entry on an iPhone as potentially exposed and move those funds to a new wallet generated on a clean device.

Is it safe to use any Firefox extension for a crypto wallet?
Extensions from the wallet vendor’s own verified listing, installed directly from an official link on the vendor’s site, remain the standard approach most wallets support. The risk in this campaign came from clones impersonating those vendors, not from official extensions themselves.

What is a BIP39 recovery phrase, and why do both attacks target it specifically?
BIP39 is the standard most crypto wallets use to turn a random number into a human-readable list of 12 or 24 words. That phrase can recreate every private key in a wallet, which makes it the single most valuable piece of data an attacker can steal, more valuable than any individual transaction signature.

Did either campaign affect hardware wallets like Ledger or Trezor directly?
Not based on current reporting. Both campaigns targeted software wallets and the recovery phrases tied to them. Hardware wallets that never expose a seed phrase to a connected computer or phone are not vulnerable to this specific attack method, though users should still avoid storing a written or photographed backup of that phrase on a networked device.

How does this compare to the September 2026 Bitget hack?
Bitget’s $387.5 million loss came from a zero-day in third-party exchange security software, affecting the exchange’s own hot and warm wallets rather than individual customers’ seed phrases. These two October campaigns are unrelated incidents targeting individual wallet holders directly, not exchange infrastructure.

Will Mozilla or Apple compensate victims of these attacks?
No compensation program has been announced by either company as of this writing. Cryptocurrency theft through user-installed software generally falls outside platform liability, which is part of why security researchers consistently recommend prevention over after-the-fact recovery.