Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

GreedyBear Crypto Scam Nets $1M Through Malicious Extensions and Malware

Author
Raymond Munene
Raymond Munene
Crypto Writer
Fact Checked by Joshua Downes
Last updated: August 8, 2025
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
GreedyBear Crypto Scam Nets $1M Through Malicious Extensions and Malware

Highlights:

  • GreedyBear crypto scam used 150 weaponized Firefox extensions to steal wallet credentials.
  • The group deployed nearly 500 crypto-targeting malware programs.
  • All attacks operated through a single coordinated command server.

A cybercrime organization called GreedyBear has executed a significant crypto theft. Koi Security, a cybersecurity firm, has associated the campaign with more than $1 million in stolen funds. The group used a fake wallet extension, crypto-focused malware, and scam websites. According to the researchers, the attack demonstrated a coordination of a scale never seen before in the crypto theft market.

Advertisement

Banner

The attack featured over 650 malicious programs against crypto wallet users. It included 150 weaponized Firefox extensions, which resembled popular wallets such as MetaMask and TronLink. These fake extensions initially looked harmless in order to be permitted in the Firefox scrutiny. Once they were trusted, they were patched with code to steal wallet passwords and private keys.

💥BREAKING NEWS 💥

GreedyBear just took crypto crime to a new level—over $1M pilfered using 150+ fake Firefox wallet extensions, malware, and scam sites. It’s like they built a fraud factory.

Have you double-checked your extensions lately? 👀 #Crypto #Web3 #Security pic.twitter.com/fZS8o4fPDo

— Cheeky Crypto (@CheekyCrypto) August 8, 2025

Multi-Vector Strategy With Extension Hollowing

Koi Security detailed a tactic called “Extension Hollowing” in the GreedyBear crypto scam. To establish trust, the group opened new accounts at the marketplaces and imported harmless tools. In addition, they flooded listings with fake positive reviews to make themselves credible. They later interchanged the code with their malicious payloads, maintaining the same naming and ratings.

This method allowed the criminals to bypass the security checks when making initial submissions. After the extensions were weaponized, they forwarded IP addresses and wallet credentials to a control server. The same infrastructure was used to coordinate ransomware demands and to host phishing websites. As security specialists affirmed, the server also processed data related to malware operations.

The malware component of the campaign contained nearly 500 Windows executables. Such files used to be shared largely through Russian websites that provided pirated software. Families of malware, such as LummaStealer and Luca Stealer, attacked wallets and encrypted devices. Hackers demanded payments in cryptocurrency to recover data access.

Scam Websites and AI-Driven Scaling

The third method of attack was based on sophisticated imitation websites. Such websites copied digital-wallet brands, hardware devices, and wallet repair services. They were finely tuned landing pages that were aimed at harvesting sensitive user information. In reality, they served as data harvesting tools for the threat agents.

All the aspects of the attack were found to be linked to a single IP address. With this single hub, GreedyBear was able to coordinate and expand operations effectively. The presence of indicators of AI-generated code hinted at the ability to expand new attacks rapidly. Consequently, this automation made detection and blocking much more challenging for defenders.

GreedyBear Crypto Scam Nets $1M Through Malicious Extensions and Malware
Source: Koi Security

The GreedyBear crypto scam evolved from the smaller Foxy Wallet campaign. The campaign initially involved only 40 malicious Firefox add-ons. The scale has tripled, pointing in the direction of expansion to Chrome. Security researchers indicate that Edge and other browsers may be targeted soon.

Crime associated with crypto is on the increase in the sector. In July alone, 17 different cases of hackers stealing $142 million occurred. Blockchain security company PeckShield noted that the losses in July increased by 27% compared to June. Although the numbers amount to less than the July 2024 figure of 266 million, they are still substantial.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Tags

Crypto ScamCybercrimeGreedyBearHackMalware
Raymond Munene
Author

Raymond Munene

Raymond Munene is a crypto content writer who contributes to Crypto2Community. With over three years of experience, he is interested in Bitcoin, Blockchain, and Technical Analysis. Focusing on daily market analysis, his research helps traders and investors alike. His particular interest in cryptocurrency and blockchain aids his audience.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Binance Eyes Philippines Return Through SEC Sandbox Deal
  • OKB Price Analysis – 1,574% Volume Explosion Fuels Breakout Hopes as Bulls Target $117 Rally 
  • Near Protocol Price Prediction – NEAR Targets $3 as Trading Volumes Surge

Related Articles:

Binance Eyes Philippines Return Through SEC Sandbox Deal
Binance Eyes Philippines Return Through SEC Sandbox Deal
Crypto News6 hours ago
Raymond Munene
By Raymond Munene5/26/2026
OKB Price Analysis – 1,574% Volume Explosion Fuels Breakout Hopes as Bulls Target $117 Rally 
OKB Price Analysis – 1,574% Volume Explosion Fuels Breakout Hopes as Bulls Target $117 Rally 
Crypto News7 hours ago
Syed Ali Haider
By Syed Ali Haider5/26/2026
Near Protocol Price Prediction – NEAR Targets $3 as Trading Volumes Surge
Near Protocol Price Prediction – NEAR Targets $3 as Trading Volumes Surge
Crypto News7 hours ago
Syed Ali Haider
By Syed Ali Haider5/26/2026

Advertisement

Banner

Advertisement

Banner

🔥Latest offers

Play Now

9.85 Stars

🔥 Get up to 60% with all rewards

Claim Bonus

9.65 Stars

💸 300% deposit bonus up to 20,000 USD

Visit eToro

9.95 Stars

Best Crypto Exchange 2025

Virtual currencies are highly volatile. Your capital is at risk.

Visit KuCoin

9.55 Stars

Trading features & low fees

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • Binance Eyes Philippines Return Through SEC Sandbox Deal
  • OKB Price Analysis – 1,574% Volume Explosion Fuels Breakout Hopes as Bulls Target $117 Rally 
  • Near Protocol Price Prediction – NEAR Targets $3 as Trading Volumes Surge
  • Bitcoin ETFs Drive Massive Crypto Outflows During Worst Week of 2026
  • Bitget’s Reality Launches Regulated RWA Platform for Tokenized Stocks
  • Bitwise Launches Canton ETP to Offer Regulated Exposure to CC Token
  • Uniswap Phishing Scams on Google Ads Drain Over $400K From Crypto Wallets
  • XRP Bearish Sentiment Surges to Extreme Levels Amid Market Uncertainty
  • Next Altcoins to Explode, May 26 – Render, NEAR Protocol, Hyperliquid
  • OKX Launches Exchange OS to Help Developers Build Onchain Trading Markets
  • Crypto Weekly Market Wrap May 25 – Policy Shifts, Treasury Moves & Security Breaches
  • Bitcoin Demand Falls to Lowest Level as Market Sentiment Turns Bearish
  • Blockaid Flags $3M SquidRouterModule Exploit Draining 86 Gnosis Safes
  • Ethereum Price Analysis – Staking and Institutional Demand Fuel Bullish Outlook Toward $3,000
  • Bitcoin Price Prediction – Weak Institutional Demand Puts BTC at Risk of Drop Toward $65K
  • Tether, Georgia Move to Bring Georgian Lari On-Chain with GEL₮ Stablecoin
  • Top Cryptos to Watch Today, May 25 – BNB, Tron, Hyperliquid
  • Socket Warns TrapDoor Malware Is Targeting Crypto Developers
  • Coinbase CEO Outlines Eight Crypto Upgrades Needed to Fix Global Finance
  • Why the Crypto Market is Down Today?