All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

Created at 25 Aug · 2:16 PM1 source↑ Market-relevant
IN SHORT

Security firm Socket has identified 77 Firefox extension identities, confirming 40 as malicious, that impersonate crypto wallets like OKX and Rabby Wallet. These extensions aim to steal recovery phrases and credentials, with some initially posing as sports score apps before being updated with malware.

Key Numbers

77Firefox extension identities linked to campaign
40Confirmed malicious extensions
9Extensions that started as sports apps before becoming malware
13Modified Rabby Wallet builds that sent stored data externally
5Extensions that collected saved credentials and clipboard contents
March 9 to August 3Campaign active period

Who's Involved

Socket
Security firm that linked extensions to crypto-stealing malware
OKX
Impersonated crypto wallet provider
Rabby Wallet
Impersonated crypto wallet provider
TronLink
Impersonated crypto wallet provider
Mozilla
Signed the malicious Firefox extensions
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

↳ Why This Matters

This campaign highlights a persistent threat vector for cryptocurrency users, demonstrating how malicious actors exploit trusted browser extension platforms to steal digital assets by impersonating legitimate services and even repurposing seemingly harmless applications.

Key facts

  • Security firm Socket identified 77 Firefox extension identities linked to crypto-stealing malware.
  • Forty of these extensions were confirmed as malicious, impersonating popular crypto wallets.
  • Some extensions began as sports score apps before being updated with wallet-stealing code.
  • The malware aimed to capture users' recovery phrases and private keys.
  • The campaign was active between March 9 and August 3.

Dozens of counterfeit cryptocurrency wallet extensions have been discovered on Firefox, designed to steal users' sensitive recovery phrases and credentials. Security firm Socket linked 77 extension identities to a campaign dubbed the 'Offside Wallet Theft Factory,' confirming 40 as malicious. These extensions impersonated popular wallets such as OKX, Rabby Wallet, and TronLink, often using similar names to deceive users.

Some of these malicious add-ons initially functioned as legitimate sports score applications, publishing live football and basketball scores. Over time, their code was quietly updated to include wallet-stealing malware, leveraging their existing install base and positive review history. The campaign, identified by shared code, infrastructure, and publishing patterns, was active from March 9 to August 3, with several extensions remaining live even after being reported.

Socket's research detailed various methods used by the malware, including fake wallet interfaces that captured typed recovery phrases or private keys, and modified versions of real wallet code that exfiltrated stored account data. Other extensions focused on collecting saved credentials and clipboard contents. The firm advised users who may have entered sensitive information into these extensions to treat their wallets as permanently compromised and transfer funds to a new, secure wallet.

Frequently asked questions

It is the name given by security firm Socket to a campaign involving dozens of fake Firefox browser extensions designed to steal cryptocurrency wallet recovery phrases and credentials.

They impersonated legitimate crypto wallets, presenting fake interfaces to capture recovery phrases or private keys, or modified existing wallet code to send stored account data to external servers. Some also collected saved credentials and clipboard contents.

No, some malicious extensions initially operated as sports score apps before being updated with wallet-stealing malware, using their established user base and review history to appear legitimate.

Users should immediately treat their wallet as compromised, uninstall the suspicious extension, and move all funds to a newly created, secure wallet.

What Happens Next

01Users are advised to uninstall any suspicious extensions and move funds to new wallets.
02Further investigation into the operators behind the 'Offside Wallet Theft Factory' campaign may continue.
CME Headlines
  • Can Bitcoin's Long-Term Catalysts Overcome Recent Headwinds?
    24 Aug · 3:00 PM
  • Product Modification Summary: Add Offset Eligibility to Bitcoin Futures, Micro Bitcoin Futures, Ether Futures and Micro Ether Futures Contracts — Effective September 14, 2026
    19 Aug · 9:15 PM
  • Amendments to CME Rule 855. (“Offsetting Positions for Different-Sized Contracts”) – Contracts Eligible for Offset Table to Include Bitcoin Futures, Micro Bitcoin Futures, Ether Futures and Micro Ether Futures Contracts
    19 Aug · 7:45 PM

How It Developed

Security firm Socket linked 77 Firefox extension identities to a campaign called the Offside Wallet Theft Factory.
Forty of these extensions were confirmed as malicious, impersonating crypto wallets like OKX, Rabby Wallet, and TronLink.
Some malicious extensions initially functioned as sports score apps before being updated to steal crypto recovery phrases.
The campaign ran from March 9 to August 3, with several malicious extensions still active when reported.
Malicious add-ons harvested recovery phrases, private keys, or stored account data by mimicking wallet interfaces or modifying real wallet code.
Socket advised users who entered recovery phrases into these extensions to move funds to a new wallet immediately.

Sources

T1
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing MalwareDecrypt

Related Stories

Galaxy: 87% of Bitcoin stolen in Coldcard hack remains unmoved
25 Aug · 8:52 AM
Chainalysis-led operation flags 7,700 accounts in child abuse probe
25 Aug · 1:17 PM
US Sanctions Iran's Crypto Sector, Cites $100M in Oil Payments
25 Aug · 5:41 AM
Business Owner Convicted of $24M Crypto Ponzi Scheme
25 Aug · 8:11 AM
Crypto Fund Founder Convicted of Fraud Over Fake Trading Bot
25 Aug · 3:00 PM