Crypto news report · source clearly identified
Socket Identifies 40 Malicious Firefox Extensions Draining Crypto Wallets
Security firm Socket confirmed 40 Firefox add‑ons with malicious behavior that stole crypto wallet secrets, including nine that originally appeared as sports‑score tools.

Software supply‑chain security firm Socket reported that 40 Firefox extensions were confirmed to contain malicious code designed to steal cryptocurrency wallet credentials. The campaign, dubbed the “Offside Wallet Theft Factory,” operated from at least March through August and included extensions that previously offered sports‑score utilities.
Scope of the malicious extensions
Out of 77 identified extension IDs, 40 were proven to perform theft, while the remaining 37 were deceptive sports‑score shells without confirmed payloads. The malicious extensions employed several techniques:
- Remote‑controlled phishing loaders (7 extensions)
- Direct capture of recovery phrases, private keys, or other wallet secrets (15 extensions)
- Modified clones of Rabby wallet software that exfiltrated serialized keyrings before local encryption (13 extensions)
- Credential and clipboard data collection (5 extensions)
Notable extension histories
Socket traced nine IDs that transitioned from sports‑score tools to malicious versions, for example:
- bright‑save‑[email protected] → Quick (7.4.0) → Rabbit For Desktop (8.20.10)
- swift‑clip‑[email protected] → Dial Open Pro (7.23.25) → Web3 & EVM (9.50.10)
- deep‑tip‑[email protected] → Quick Shield (5.7.1) → Rby‑WALLEТ (6.7.10)
Impact on users
Any wallet whose recovery phrase, private key, or keyring was entered into a compromised extension should be considered compromised. Uninstalling the extension does not revoke the exposed secret.
Recommended actions
- Generate a new wallet with a fresh recovery phrase and transfer remaining assets.
- If only credentials or clipboard data were captured, change affected passwords and review recent transaction addresses.
- Install extensions only from official wallet provider sites.
Mozilla’s response
Mozilla employs automated risk indicators and human review to detect malicious wallet extensions. Several of the reported add‑ons were still live when Socket notified Mozilla; one remote‑controlled phishing add‑on, 0KX WEB3, was removed after being found active with seven users.
Open questions
Socket documented the theft capabilities and exfiltration infrastructure but did not disclose confirmed victim counts, specific transaction hashes, or total financial loss.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- August 26, 2026, 4:00 AM
- Original headline
- 40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools