Firefox users were targeted by a pipeline of counterfeit crypto wallet extensions, with some of the apps spending months as live football score tools before being quietly turned into recovery phrase stealers.
Socket’s threat research team said last week that it connected 77 Firefox extension identities through shared code, infrastructure, and publishing patterns, and confirmed 40 as malicious. Mozilla signing records place the activity from March 9 to August 3. Socket said several of the extensions were still live when it reported them.
Wallet brands copied across dozens of extensions
The malicious add-ons impersonated OKX, Rabby Wallet, TronLink, and other Web3 products. In many cases, the names used look close enough to the legitimate brands to pass a quick glance.
Socket said roughly half of the malicious extensions presented a convincing wallet interface and asked the user to import an existing wallet. When the user entered a recovery phrase or private key, the extension captured it.
Another 13 extensions were modified Rabby builds that appeared to work normally while sending stored wallet account data to an outside server as that data was saved. Five others collected saved credentials and clipboard contents.
37 other identities posed as unrelated tools
Socket said the broader Firefox campaign involved 77 extension identities in total:
- 40 stole wallet secrets and credentials.
- Another 37 posed as unrelated tools but displayed sports scores.
- Nine started as score apps before later updates turned them into wallet malware.
Those additional 37 identities were presented as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran live sports-score applications. Socket said they all shared a single hardcoded credential for a legitimate sports data provider.
Score apps later updated into wallet malware
In nine confirmed malicious cases, the extensions followed the same path. They were first published under the same Firefox IDs as football, basketball, NBA, or American football score apps. Later updates replaced that code with wallet stealers, while keeping whatever install base and review history the original apps had accumulated.
Socket named the campaign the “Offside Wallet Theft Factory” because of that pattern. The company also said it has not established that every extension in the cluster was operated by a single actor.
Low permission requests did not make the extensions safe
One counterfeit OKX wallet asked for only two permissions, storage and tabs, because it did not need to search the browser for anything. Socket said the extension simply loaded a remote page and waited for the user to type in a recovery phrase. The example shows the limits of judging an extension only by the access it requests.
Users who entered a phrase or key should move funds
Socket said anyone who entered a recovery phrase or private key into one of the affected extensions should treat it as “permanently compromised” and move funds to a new wallet. Removing the extension does not revoke a phrase that has already been sent elsewhere, the team said.
Browser extensions have become a recurring route for crypto theft. Decrypt noted that a Chrome extension was recently exposed as having siphoned fees from Solana traders for months before being caught. Attackers have also hidden stealers in pirated software, a fake Mac clipboard app, and PC games distributed through Steam.

