Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed Malicious

Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed Malicious

N
News Editor
2026-08-25 14:10:05
Socket’s threat research team said it linked 77 Firefox extension identities through shared code, infrastructure, and publishing patterns, and confirmed 40 of them as malicious. According to the company, the extensions impersonated crypto wallet and Web3 brands including OKX, Rabby Wallet, and TronLink, with many designed to trick users into importing an existing wallet and entering a recovery phrase or private key. Mozilla signing records placed the campaign between March 9 and August 3, and Socket said several of the extensions were still live when it reported them. The researchers also found that 37 other extension identities were presented as unrelated utilities but actually displayed live sports scores. In nine confirmed cases, football, basketball, NBA, or American football score apps were later updated into wallet-stealing malware, allowing the operators to retain the install base and review history built by the original apps. Socket named the pattern the “Offside Wallet Theft Factory,” while saying it has not established that every extension was run by a single operator. The firm warned that users who entered a recovery phrase or private key into any of the affected extensions should treat those credentials as permanently compromised and move funds to a new wallet.

Firefox users were targeted by a pipeline of counterfeit crypto wallet extensions, with some of the apps spending months as live football score tools before being quietly turned into recovery phrase stealers.

Socket’s threat research team said last week that it connected 77 Firefox extension identities through shared code, infrastructure, and publishing patterns, and confirmed 40 as malicious. Mozilla signing records place the activity from March 9 to August 3. Socket said several of the extensions were still live when it reported them.

Wallet brands copied across dozens of extensions

The malicious add-ons impersonated OKX, Rabby Wallet, TronLink, and other Web3 products. In many cases, the names used look close enough to the legitimate brands to pass a quick glance.

Socket said roughly half of the malicious extensions presented a convincing wallet interface and asked the user to import an existing wallet. When the user entered a recovery phrase or private key, the extension captured it.

Another 13 extensions were modified Rabby builds that appeared to work normally while sending stored wallet account data to an outside server as that data was saved. Five others collected saved credentials and clipboard contents.

37 other identities posed as unrelated tools

Socket said the broader Firefox campaign involved 77 extension identities in total:

  • 40 stole wallet secrets and credentials.
  • Another 37 posed as unrelated tools but displayed sports scores.
  • Nine started as score apps before later updates turned them into wallet malware.

Those additional 37 identities were presented as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran live sports-score applications. Socket said they all shared a single hardcoded credential for a legitimate sports data provider.

Score apps later updated into wallet malware

In nine confirmed malicious cases, the extensions followed the same path. They were first published under the same Firefox IDs as football, basketball, NBA, or American football score apps. Later updates replaced that code with wallet stealers, while keeping whatever install base and review history the original apps had accumulated.

Socket named the campaign the “Offside Wallet Theft Factory” because of that pattern. The company also said it has not established that every extension in the cluster was operated by a single actor.

Low permission requests did not make the extensions safe

One counterfeit OKX wallet asked for only two permissions, storage and tabs, because it did not need to search the browser for anything. Socket said the extension simply loaded a remote page and waited for the user to type in a recovery phrase. The example shows the limits of judging an extension only by the access it requests.

Users who entered a phrase or key should move funds

Socket said anyone who entered a recovery phrase or private key into one of the affected extensions should treat it as “permanently compromised” and move funds to a new wallet. Removing the extension does not revoke a phrase that has already been sent elsewhere, the team said.

Browser extensions have become a recurring route for crypto theft. Decrypt noted that a Chrome extension was recently exposed as having siphoned fees from Solana traders for months before being caught. Attackers have also hidden stealers in pirated software, a fake Mac clipboard app, and PC games distributed through Steam.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.