⚡️⚠ ALERT - 40 Firefox extensions have been identified as ca...

FLASH

npub1f4uyypghstsd8l4sxng4ptwzk6awfm3mf9ux0yallfrgkm6mj6es50r407

hex

d01a7a49df13652f5ced78705045ebe570d3b8fef14b216264f1c589d42a4a80

nevent

nevent1qqsdqxn6f803xef0tnkhsuzsgh472uxnhrl0zjepvfj0r3vf6s4y4qqprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsy67zzq5tc9cxnl6crf52s4hptdwhyaca5j7r8jwll535tdadedvc642r49

Kind-1 (TextNote)

2026-08-26T18:19:52Z

⚡️⚠ ALERT - 40 Firefox extensions have been identified as capable of stealing your cryptocurrencies.

Cybersecurity researchers at Socket have uncovered a large-scale campaign involving 77 interconnected Firefox extensions that has been active since at least March 2026.

Of these, 40 have been confirmed as malicious, with some posing as well-known wallets such as OKX, Rabby Wallet, or TronLink.

The way they operate is particularly dangerous: some extensions directly retrieve recovery phrases, private keys, or wallet data, then transmit them to the attackers. Others display fake interfaces that simply ask the victim to import their seed phrase. Once entered, the hackers have everything they need to restore the wallet elsewhere and drain the cryptocurrency. https://blossom.primal.net/16fe5d4ae7e674cb8a7513c5ca084e3b01fa691693eb22c626c43397b4c11e22.jpg

原始 JSON

{
  "kind": 1,
  "id": "d01a7a49df13652f5ced78705045ebe570d3b8fef14b216264f1c589d42a4a80",
  "pubkey": "4d7842051782e0d3feb034d150adc2b6bae4ee3b49786793bffa468b6f5b96b3",
  "created_at": 1787768392,
  "tags": [],
  "content": "⚡️⚠ ALERT - 40 Firefox extensions have been identified as capable of stealing your cryptocurrencies.\n\nCybersecurity researchers at Socket have uncovered a large-scale campaign involving 77 interconnected Firefox extensions that has been active since at least March 2026.\n\nOf these, 40 have been confirmed as malicious, with some posing as well-known wallets such as OKX, Rabby Wallet, or TronLink.\n\nThe way they operate is particularly dangerous: some extensions directly retrieve recovery phrases, private keys, or wallet data, then transmit them to the attackers.\nOthers display fake interfaces that simply ask the victim to import their seed phrase. Once entered, the hackers have everything they need to restore the wallet elsewhere and drain the cryptocurrency. https://blossom.primal.net/16fe5d4ae7e674cb8a7513c5ca084e3b01fa691693eb22c626c43397b4c11e22.jpg",
  "sig": "a86c0a4e4b5dd3f09bd239f5a312e74080ba3135358745090fa0579ca779c7f19f0ded6430884045a1eccc4812e6ae97521f543e7a72118f6ff3b3f09e387901"
}