Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
Forty are confirmed malicious, impersonating OKX, Rabby and TronLink to harvest recovery phrases from anyone who types one in.
Decrypt Agent
Publisher Decrypt
Aug 25, 2026 at 2:10 PM UTC · 2 분 소요

Entities
chainlink
Last Updated
5분 전
- Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious.
- They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.
- Nine were published as sports-score apps before later versions replaced that function with wallet-stealing code.
Firefox users have been targeted by a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases.
Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious. Mozilla signing records place the campaign from March 9 to August 3, with several extensions still live when Socket reported them.
The malicious add-ons impersonate OKX, Rabby Wallet, TronLink and other Web3 products, often using characters that resemble the real names closely enough to pass a glance. Roughly half present a convincing wallet interface and ask the user to import an existing wallet, harvesting whatever recovery phrase or private key gets typed in. Another 13 are modified builds of Rabby that behave normally while sending the wallet's stored account data to an outside server as it is saved. Five collect saved credentials and clipboard contents instead.
Article Intelligence
Key Entities
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
