Key Takeaways
40 Fake Firefox Crypto Wallet Extensions Exposed Stealing Users’ Secrets and Credentials
Security researchers have identified 40 malicious Firefox extensions designed to steal crypto wallet recovery phrases, private keys, and account credentials.
Yahoo Tech
Publisher
Aug 27, 2026 at 9:14 AM UTC · 2 dk okuma
Security researchers have identified 40 malicious Firefox extensions designed to steal crypto wallet recovery phrases, private keys, and account credentials.
The extensions are part of a wider cluster of 77 Firefox add-ons linked through shared code, infrastructure and publishing patterns.
Some malicious extensions first appeared as sports-score or utility apps, later evolving into crypto-stealing tools.
Firefox users are facing a new crypto security threat after researchers uncovered 40 malicious browser extensions capable of stealing wallet recovery phrases, private keys, and login credentials.
Socket's Threat Research team said the extensions belong to a wider network of 77 Firefox add-ons that share code, infrastructure and publishing patterns. Researchers have provisionally named the operation the "Offside Wallet Theft Factory."
The campaign has been active since at least March 2026 and has continued into August, according to Socket. Mozilla signing records reviewed by the researchers covered versions published between March 9 and Aug. 3, with activity particularly heavy in April and late July.
Fake Firefox Extensions Target OKX, Rabby and TronLink Users
The malicious add-ons impersonated popular Web3 products, including OKX, Rabby Wallet and TronLink, making them appear similar to legitimate crypto wallet extensions.
Article Intelligence
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
