77 Firefox Extensions Tied to Crypto Wallet Theft Operation
- Users should immediately remove any suspicious Firefox extensions linked to cryptocurrency wallets to prevent further data theft.
- Anyone who has entered sensitive wallet information into affected extensions must migrate their assets to secure wallets.
- Install wallet extensions only from official developer websites to minimize the risk of falling victim to malicious add-ons.
A network of 77 Firefox extensions has been linked to a campaign targeting cryptocurrency wallets and user credentials, with some add-ons able to steal recovery phrases and wallet data during otherwise normal wallet setup and storage operations.
Security firm Socket confirmed malicious behavior in 40 of the extensions. Another 37 were deceptive sports-score applications tied to the same broader publishing operation, although researchers found no wallet- or credential-stealing payload in the versions they analyzed.
The campaign, provisionally named Offside Wallet Theft Factory, has operated since at least March 2026 and remained active into August. Mozilla signing records reviewed by Socket covered versions published between March 9 and August 3.
Fake wallets capture secrets at the source
Several extensions impersonated OKX, Rabby Wallet, TronLink and other Web3 products. Seven used attacker-controlled Supabase projects to remotely activate phishing pages, allowing an extension to appear harmless until its operators switched on the malicious content.
Another 15 extensions captured recovery phrases, private keys or similar secrets and sent them through attacker-controlled Cloudflare Workers, according to the Socket investigation.
A separate group of 13 modified Rabby-based extensions went further. They altered Rabby’s wallet-storage process to exfiltrate serialized keyring data before the legitimate software encrypted it locally. That meant local wallet encryption offered no protection once the malicious code had intercepted the data.
Five more extensions harvested credentials and clipboard contents and transmitted them to shared command-and-control infrastructure.
Anyone who entered a recovery phrase or private key into an affected extension should consider that secret permanently exposed. Removing the add-on can stop further collection, but it cannot invalidate information already stolen; assets tied to the exposed seed should instead be migrated using appropriate recovery steps.
Sports apps provided a staging ground
The remaining 37 extensions advertised functions including VPN access, password generation, currency conversion and screenshot tools while actually serving football, basketball, NBA or hockey scores.
More importantly, historical versions showed nine confirmed malicious extension identities previously operating as similar sports-score shells before later updates introduced wallet-stealing code.
Mozilla has previously said it uses automated risk scoring and human review to detect fraudulent crypto-wallet extensions, while acknowledging that attackers continually adjust their methods to evade detection. Mozilla’s guidance recommends installing wallet extensions only through links provided by the wallet developer’s official website.
Socket said the evidence points to a common publishing pipeline or closely related operators, but does not yet establish that a single threat actor controlled all 77 extensions.
