40 Firefox extensions confirmed malicious in wallet-theft campaign
Socket linked 77 Firefox extension identities to a campaign that impersonated OKX, Rabby and TronLink; 40 were confirmed malicious and users who entered wallet secrets should treat them as compromised.
By The Third AnglePublished 3 min read
Illustrative cybersecurity imagery; it does not depict the Firefox extensions or the Socket investigation. Photo: Unsplash · Unsplash License
Security firm Socket linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, with 40 confirmed malicious, according to its threat research and a follow-up overview. The extensions impersonated OKX, Rabby Wallet, TronLink and other Web3 products to capture recovery phrases, private keys, credentials or clipboard data.
Socket said the campaign's signed extensions were active from at least March through August 2026. Another 37 identities behaved as deceptive sports-score shells rather than confirmed wallet stealers in the analyzed builds, while nine confirmed malicious identities had previously used sports-score versions before changing behavior.
The extension identity can outlive the code
The security research found that some extensions first appeared to provide football, basketball or other sports scores and later delivered wallet-stealing code under the same Firefox identity. Other examples used lookalike wallet names or modified Rabby code to exfiltrate stored keyrings when the wallet was used.
That makes a clean install history or modest permission list an incomplete safety signal. Socket documented one counterfeit OKX extension that requested only storage and tabs because it loaded a remote page and waited for a user to enter a recovery phrase.
A seed phrase cannot be rotated
Socket's guidance is direct: anyone who entered a recovery phrase or private key into one of the malicious extensions should treat the wallet as permanently compromised and move assets to a new wallet. Uninstalling the extension can stop further collection, but it cannot recall a secret that was already transmitted.
The investigation identifies the extensions and technical links, but does not establish a single operator behind every identity or quantify victim losses. The supportable warning is narrower: wallet users should install extensions only from links published by the wallet's official site and should never enter an existing recovery phrase into an unverified browser add-on.