Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases

Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrases

N
News Editor
2026-08-25 14:17:21
Security firm Socket said it found a cluster of malicious cryptocurrency wallet extensions targeting Firefox users and tied them to an operation it calls "Offside Wallet Theft Factory." The company linked 77 extension identities to the campaign, with 40 confirmed as malicious, and said the activity ran for at least from March to August 2026. The extensions mainly impersonated well-known Web3 wallets including OKX, Rabby Wallet and TronLink, using highly convincing wallet interfaces to trick users into importing existing wallets and handing over seed phrases or private keys. Socket said roughly half of the malicious extensions directly prompted users to enter seed phrases. Another 13 were tampered Rabby builds that sent wallet account data to external servers when users saved account information, while five collected stored credentials and clipboard contents. Socket also found that at least nine of the malicious extensions had previously operated as sports score apps covering football, basketball and the NBA, building up users and reviews before later switching to wallet-stealing code through updates. It warned that anyone who entered a seed phrase or private key into the affected extensions should treat those credentials as permanently compromised and move funds to a brand-new wallet immediately.

Security firm Socket said it has identified a batch of malicious cryptocurrency wallet extensions targeting Firefox users and linked them to an attack campaign called "Offside Wallet Theft Factory."

Socket said it has tied 77 extension identities to the operation, with 40 confirmed as malicious. The activity lasted for at least from March to August 2026.

Extensions posed as major Web3 wallets

According to Socket, the extensions mainly impersonated well-known Web3 wallets including OKX, Rabby Wallet and TronLink. They used highly realistic wallet interfaces to persuade users to import existing wallets, then stole seed phrases or private keys.

Roughly half of the malicious extensions directly asked users to enter seed phrases. Another 13 were tampered versions of Rabby that sent data to external servers when users saved wallet account information. Five more extensions collected stored credentials and clipboard contents.

Some first operated as sports score apps

Socket also found that at least nine of the malicious extensions had previously been run as sports score applications focused on football, basketball and the NBA. After building up users and reviews, they were updated with wallet-stealing code.

In addition, 37 other extensions were disguised as tools such as password generators, VPNs and exchange-rate converters, while actually running sports score programs.

Socket warning to affected users

Socket said users who had entered a seed phrase or private key into any of the related extensions should consider their wallet credentials permanently exposed. Uninstalling the extension alone cannot undo the leak once the seed phrase or private key has already been sent out, and users should move assets to a completely new wallet immediately.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.