-
Security researchers found 40 Firefox extensions that steal wallet secrets or account data.
-
The extensions mimic OKX, Rabby Wallet, TronLink and other Web3 products.
-
Researchers linked the 40 extensions to 37 deceptive sports-score add-ons in a wider campaign.

Firefox users face a new warning. Researchers found browser tools built to steal crypto wallet data. The case shows how a trusted add-on can become a threat to both coins and online accounts.
Socket Threat Research found 77 linked Firefox add-ons. It found clear theft in 40 of them. The other 37 use fake sports-score apps. The tested versions showed no clear wallet or login theft.
Socket calls the campaign “Offside Wallet Theft Factory.” The group has run it since at least March 2026. It was still active in August. Researchers have not linked it to a known crime group.
Fake Wallets Target Valuable Secrets
The malicious extensions pretend to be legitimate Web3 brands, including Rabby Wallet, OKX and TronLink. Some even use names resembling typical web browser extensions.
The security firm identified 15 extensions that steal recovery phrases, private keys or other types of wallet secrets. The extension sends all the information it steals to Cloudflare Workers run by the thieves.
A recovery phrase can help attackers restore a wallet on another device. And with the private key, they can gain full access to all the funds inside. The worst part? Once an attacker obtains wallet secrets, deleting the extension won’t save the wallet.
Rabby Clones Steal Keyrings
Thirteen other add-ons use altered Rabby Wallet code. These add-ons extract wallet keyrings before they’re encrypted on the user’s device. The software is able to extract both new and imported 12-word and 24-word recovery phrases. Afterward, it passes them to the thief’s servers.
Socket also detected fakePortal and Portal Web add-ons. These can provide wallet import screens and request the user’s recovery phrase or private key. One fake OKX add-on, called “0KX WEB3,” replaces the letter ‘O’ in OKX with zero.
These fake add-ons do not provide any legitimate wallet functions. Instead, they load a Web3 page from the web. This page requests the user to create or import a wallet. Mozilla had already removed the add-on before Socket published the report.
Clipboard and Login Data are also at Risk
The campaign also targets data beyond crypto wallets. Five add-ons collect login data and clipboard data. They send it to a fixed server run by the thieves. Clipboard data can hold passwords, backup codes, wallet addresses and other private text.
Seven other add-ons use Supabase projects run by the thieves. The projects tell the add-ons which fake page to load. Supabase and Cloudflare are real services. The thieves abuse them to run parts of the scam.
Sports Apps Helped Hide the Campaign
The wider group shows another part of the plan. Socket found 37 add-ons that look like simple browser tools. In fact, they run sports-score apps for football, basketball, NBA and hockey. The tested versions showed no clear wallet, login or clipboard theft. Socket calls them suspicious and deceptive. It does not call them confirmed malware.
Their past links them to the wider campaign. Nine confirmed bad add-ons once used sports-score code. Later updates turned them into wallet thieves. The updates kept the same Firefox IDs. This matters because a user may trust an add-on they installed for a harmless task. A later update can change its role.
A Repeatable System for Theft
Socket found signs of one shared publishing system. The signs include reused code, similar Firefox IDs, shared servers and repeated names. This points to a system that can make and change many add-ons. Socket has not said one person or group runs them all. Attribution remains under review.
The findings show why add-on stores remain a target. Thieves can use known brands and simple tools to gain trust. They can then change the code or send users to a fake wallet page.
How Firefox Users Can Stay Safe
Crypto users should get wallet add-ons from the maker’s official site. Just using the Firefox Add-ons store will not be enough, because blindly trusting the search results may lead to installing a virus or a fraudulent application.
MI6 has also embraced the dark web for its own operations. In September 2025, the UK intelligence agency launched Silent Courier, a secure dark web portal to recruit spies worldwide, with outgoing chief Sir Richard Moore announcing that the agency’s “virtual door is open” to those with sensitive information on global instability, terrorism, or hostile intelligence activity.
In order to avoid this from happening, before installing an add-on, always check the basic info on its creator, its name, its rating, as well as the permissions it requires.
Pay special attention to slight spelling mistakes of famous brands. Consider any demands for a recovery phrase or secret key as a huge red flag.
Mozilla previously warned about such fake cryptocurrency wallet extensions. In 2025, it said its Add-ons team had found hundreds of scam wallets over several years. The new Socket report shows the risk remains. Browser add-ons can sit close to private data, including wallet secrets.
For crypto users, one bad install can turn a trusted browser into a path to lost funds. The safest step is simple: use only wallet tools from a source you can verify.