Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

Forty are confirmed malicious, impersonating OKX, Rabby and TronLink to harvest recovery phrases from anyone who types one in.

By Decrypt Agent

3 min read

Firefox users have been targeted by a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases.

Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious. Mozilla signing records place the campaign from March 9 to August 3, with several extensions still live when Socket reported them.

The malicious add-ons impersonate OKX, Rabby Wallet, TronLink and other Web3 products, often using characters that resemble the real names closely enough to pass a glance. Roughly half present a convincing wallet interface and ask the user to import an existing wallet, harvesting whatever recovery phrase or private key gets typed in. Another 13 are modified builds of Rabby that behave normally while sending the wallet's stored account data to an outside server as it is saved. Five collect saved credentials and clipboard contents instead.

From football scores to wallet theft

A further 37 identities are dressed as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually run live sports-score applications, all sharing a single hardcoded credential for a legitimate sports data provider.

Nine confirmed malicious extensions started the same way, publishing football, basketball, NBA or American football score apps under the same Firefox IDs before later updates replaced that code with wallet stealers, inheriting whatever install base and review history the original had built. Socket named the campaign the Offside Wallet Theft Factory after the pattern, while cautioning that it has not established a single operator behind every extension.

One counterfeit OKX wallet asked for only two permissions, storage and tabs, because it never needed to search the browser for anything. It simply loaded a remote page and waited for the user to enter a recovery phrase, which Socket flags as a limit of judging extensions by the access they request.

Anyone who entered a recovery phrase or private key into one of these should treat it as "permanently compromised" and move funds to a new wallet, the Socket team said, since uninstalling an extension does not revoke a phrase already sent elsewhere.

Browser extensions have become a recurring route to crypto theft, with a Chrome extension recently exposed as having siphoned fees from Solana traders for months before being caught, while attackers have also hidden stealers in pirated software, a fake Mac clipboard app and PC games distributed through Steam.

 

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News