Crypto news report · source clearly identified

Socket Identifies 40 Malicious Firefox Extensions Draining Crypto Wallets

Security firm Socket confirmed 40 Firefox add‑ons with malicious behavior that stole crypto wallet secrets, including nine that originally appeared as sports‑score tools.

Software supply‑chain security firm Socket reported that 40 Firefox extensions were confirmed to contain malicious code designed to steal cryptocurrency wallet credentials. The campaign, dubbed the “Offside Wallet Theft Factory,” operated from at least March through August and included extensions that previously offered sports‑score utilities.

Scope of the malicious extensions

Out of 77 identified extension IDs, 40 were proven to perform theft, while the remaining 37 were deceptive sports‑score shells without confirmed payloads. The malicious extensions employed several techniques:

  • Remote‑controlled phishing loaders (7 extensions)
  • Direct capture of recovery phrases, private keys, or other wallet secrets (15 extensions)
  • Modified clones of Rabby wallet software that exfiltrated serialized keyrings before local encryption (13 extensions)
  • Credential and clipboard data collection (5 extensions)

Notable extension histories

Socket traced nine IDs that transitioned from sports‑score tools to malicious versions, for example:

Impact on users

Any wallet whose recovery phrase, private key, or keyring was entered into a compromised extension should be considered compromised. Uninstalling the extension does not revoke the exposed secret.

Recommended actions

  • Generate a new wallet with a fresh recovery phrase and transfer remaining assets.
  • If only credentials or clipboard data were captured, change affected passwords and review recent transaction addresses.
  • Install extensions only from official wallet provider sites.

Mozilla’s response

Mozilla employs automated risk indicators and human review to detect malicious wallet extensions. Several of the reported add‑ons were still live when Socket notified Mozilla; one remote‑controlled phishing add‑on, 0KX WEB3, was removed after being found active with seven users.

Open questions

Socket documented the theft capabilities and exfiltration infrastructure but did not disclose confirmed victim counts, specific transaction hashes, or total financial loss.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
August 26, 2026, 4:00 AM
Original headline
40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools
View original report ↗