NewsCryptoDozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware Campaign

Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware Campaign

Author: Decrypt·

Key Takeaways

  • Socket linked 77 Firefox extension identities to the campaign and confirmed 40 of them as malicious.
  • The fake add-ons impersonated Web3 wallets and harvested recovery phrases, private keys, saved credentials or clipboard contents.
  • Nine extensions first appeared as sports-score apps before later updates turned them into wallet-stealing malware.
  • Mozilla signing records indicate the campaign ran from March 9 to August 3, and several extensions were still live when reported.
  • Socket said any recovery phrase or private key entered into the extensions should be treated as permanently compromised.
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware Campaign

Security firm Socket has linked 77 Firefox extension identities to a coordinated campaign it has named the Offside Wallet Theft Factory, confirming 40 of them as malicious. The counterfeit add-ons impersonate popular wallets including OKX, Rabby Wallet and TronLink, harvesting recovery phrases through fake wallet interfaces or modified versions of real wallet code.

Nine of the extensions were initially published as sports-score apps before later versions quietly replaced that functionality with wallet-stealing code.

Firefox users have been targeted by what amounts to a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being converted into tools for stealing recovery phrases. Socket's threat research team published its findings last week, linking the 77 extension identities through shared code, shared infrastructure and common publishing patterns, and confirming 40 as malicious. Mozilla signing records place the campaign between March 9 and August 3, with several extensions still live at the time Socket reported them. Mozilla requires add-ons to be signed before Firefox will install them, so those records also show the counterfeit listings passing that process for months.

Socket Threat Research uncovered a 77-extension Firefox campaign: 40 steal wallet secrets and credentials. Another 37 posed as unrelated tools but displayed sports scores. Nine began as score apps before later updates turned them into wallet malware.

— Socket (@SocketSecurity) August 19, 2026

The malicious add-ons impersonate OKX, Rabby Wallet, TronLink and other Web3 products, often using characters that closely resemble the real names — close enough to pass a glance, a form of name spoofing long known as typosquatting. Roughly half present a convincing wallet interface and ask the user to import an existing wallet, harvesting whatever recovery phrase or private key gets typed in — the credentials that can rebuild or unlock the wallet from anywhere, with no need for the victim's browser or device. Another 13 are modified builds of Rabby that behave normally while sending the wallet's stored account data to an outside server as it is saved. Five collect saved credentials and clipboard contents instead.

From football scores to wallet theft

A further 37 identities are dressed as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually run live sports-score applications, all sharing a single hardcoded credential for a legitimate sports data provider.

Nine confirmed malicious extensions started the same way, publishing football, basketball, NBA or American football score apps under the same Firefox IDs before later updates replaced that code with wallet stealers, inheriting whatever install base and review history the original had built. Firefox users rate and review add-ons on Mozilla's store, so an established, well-reviewed listing carries a credibility that a brand-new wallet extension would lack — and the update quietly transfers that standing to the malicious code. Socket named the campaign the Offside Wallet Theft Factory after the pattern, while cautioning that it has not established a single operator behind every extension.

One counterfeit OKX wallet asked for only two permissions, storage and tabs, because it never needed to search the browser for anything. It simply loaded a remote page and waited for the user to enter a recovery phrase — a case Socket flags as a limit of judging extensions by the access they request.

Anyone who entered a recovery phrase or private key into one of these extensions should treat it as "permanently compromised" and move funds to a new wallet, the Socket team said, since uninstalling an extension does not revoke a phrase that has already been sent elsewhere.

Browser extensions have become a recurring route to crypto theft. A Chrome extension was recently exposed as having siphoned fees from Solana traders for months before being caught, while attackers have also hidden stealers in pirated software, a fake Mac clipboard app and PC games distributed through Steam.