In brief
- Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious.
- They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.
- Nine were published as sports-score apps before later versions replaced that function with wallet-stealing code.
Firefox users have been targeted by a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases.
Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious. Mozilla signing records place the campaign from March 9 to August 3, with several extensions still live when Socket reported them.
Socket Threat Research uncovered a 77-extension Firefox campaign:
40 steal wallet secrets and credentials. Another 37 posed as unrelated tools but displayed sports scores. Nine began as score apps before later updates turned them into wallet malware.https://t.co/WNwoL7M0O7
— Socket (@SocketSecurity) August 19, 2026
The malicious add-ons impersonate OKX, Rabby Wallet, TronLink and other Web3 products, often using characters that resemble the real names closely enough to pass a glance. Roughly half present a convincing wallet interface and ask the user to import an existing wallet, harvesting whatever recovery phrase or private key gets typed in. Another 13 are modified builds of Rabby that behave normally while sending the wallet's stored account data to an outside server as it is saved. Five collect saved credentials and clipboard contents instead.
From football scores to wallet theft
A further 37 identities are dressed as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually run live sports-score applications, all sharing a single hardcoded credential for a legitimate sports data provider.
Nine confirmed malicious extensions started the same way, publishing football, basketball, NBA or American football score apps under the same Firefox IDs before later updates replaced that code with wallet stealers, inheriting whatever install base and review history the original had built. Socket named the campaign the Offside Wallet Theft Factory after the pattern, while cautioning that it has not established a single operator behind every extension.
One counterfeit OKX wallet asked for only two permissions, storage and tabs, because it never needed to search the browser for anything. It simply loaded a remote page and waited for the user to enter a recovery phrase, which Socket flags as a limit of judging extensions by the access they request.
Anyone who entered a recovery phrase or private key into one of these should treat it as "permanently compromised" and move funds to a new wallet, the Socket team said, since uninstalling an extension does not revoke a phrase already sent elsewhere.
Browser extensions have become a recurring route to crypto theft, with a Chrome extension recently exposed as having siphoned fees from Solana traders for months before being caught, while attackers have also hidden stealers in pirated software, a fake Mac clipboard app and PC games distributed through Steam.
decrypt.co