Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious

Socket links 77 Firefox extensions to wallet-theft campaign, says 40 are confirmed malicious

N
News Editor
2026-08-25 14:18:31
Security firm Socket has linked 77 Firefox extensions to a malicious operation it calls the "Overstep wallet theft factory," according to a report cited by Decrypt. Of those, 40 have been confirmed as malicious. The extensions allegedly impersonated Web3 products including OKX, Rabby Wallet and TronLink, either by presenting fake wallet interfaces that pushed users to import existing wallets or by using modified versions of legitimate wallet code to steal seed phrases and private keys as they were entered. Mozilla signing records cited by Socket show the activity ran from March 9 to Aug. 3, and several of the extensions were still live when the report was published. Socket said about half of the extensions displayed realistic wallet interfaces designed to capture seed phrases or private keys. Another 13 were modified Rabby builds that functioned normally while sending stored account data to external servers, while five were built to collect saved credentials and clipboard contents. Socket also found 37 extensions posing as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually running a sports scores app that shared the same hardcoded credential. Nine confirmed malicious extensions were first published as football or basketball score apps before later updates swapped in wallet-stealing code. Socket said users who entered seed phrases or private keys into any of these extensions should treat them as permanently compromised and move funds to a new wallet immediately.

Security firm Socket has linked 77 Firefox extensions to a malicious campaign it calls the "Overstep wallet theft factory," with 40 of them confirmed as malicious, according to Decrypt.

The extensions impersonated Web3 products including OKX, Rabby Wallet and TronLink. Socket said they either used fake wallet interfaces to trick users into importing wallets or relied on modified versions of real wallet code to steal seed phrases and private keys as users typed them.

Mozilla signing records show the activity ran from March 9 through Aug. 3, and several extensions were still online when Socket published its report.

Socket said about half of the extensions showed realistic wallet interfaces and asked users to import existing wallets, allowing the operators to capture seed phrases or private keys entered by users. Another 13 were modified versions of Rabby that continued to function while sending wallet-stored account data to external servers. Five others were designed to collect saved credentials and clipboard contents.

Socket also said 37 extensions posed as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, while actually running a sports scores application that shared the same hardcoded credential. Nine confirmed malicious extensions were initially published as football or basketball score apps, then later updated with wallet-stealing code.

Socket named the activity the "Overstep wallet theft factory" but said it has not confirmed that every extension in the cluster was controlled by the same operator.

The company said any user who entered a seed phrase or private key into one of these extensions should consider it "permanently compromised" and move funds to a new wallet immediately, because uninstalling the extension cannot undo the transmission of seed phrases that have already been sent elsewhere.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
10

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.