Overview
- Security firm Socket has identified 77 Firefox extension identities associated with a scheme dubbed the Offside Wallet Theft Factory, confirming 40 of these as malicious.
- These extensions impersonate known wallets such as OKX, Rabby Wallet, and TronLink, capturing recovery phrases via deceptive wallet interfaces or altered versions of legitimate wallet code.
- Nine of these extensions were initially released as sports-score applications before their functionality was transformed to include wallet-stealing capabilities.
Users of Firefox have become victims of a series of fake cryptocurrency wallet extensions, some of which had been operating for months as live football score apps before covertly shifting to recovery phrase theft.
Last week, Socket's threat research team released findings that connected 77 extension identities through common code and patterns, confirming that 40 of them are indeed malicious. Mozilla's signing records trace the timeline of this campaign from March 9 to August 3, with some extensions still active at the time of Socket's report.
Socket Threat Research uncovered a campaign involving 77 Firefox extensions:
40 of these are designed to steal wallet secrets and credentials. An additional 37 masquerade as unrelated tools but actually show sports scores. Nine started as score apps but were later updated to become wallet malware.https://t.co/WNwoL7M0O7
— Socket (@SocketSecurity) August 19, 2026
The fraudulent extensions imitate Web3 products such as OKX, Rabby Wallet, and TronLink, often using names that closely resemble the originals. Approximately half of these present a plausible wallet interface, prompting users to import existing wallets and thereby capturing any recovery phrases or private keys that are entered. Another 13 are modified versions of Rabby that function normally while simultaneously transmitting the wallet's account data to an external server. Five others gather saved credentials and clipboard information.
Transition from Sports Scores to Wallet Theft
In addition, 37 identities are disguised as password generators, dark mode switches, VPNs, currency converters, and note-taking applications, but they actually run live sports-score services, all relying on a single hardcoded credential for a legitimate sports data provider.
Nine confirmed malicious extensions began as sports score apps, providing updates for football, basketball, NBA, or American football under the same Firefox IDs, before subsequent updates converted them into wallet-stealing tools, leveraging the existing user base and review history. Socket dubbed this operation the Offside Wallet Theft Factory, while noting that the identity of a single operator behind all the extensions has not been determined.
One imitation OKX wallet requested only two permissions—storage and tabs—because it did not require browser search capabilities. Instead, it loaded a remote page and awaited user input of a recovery phrase, which Socket highlighted as a limitation in assessing extensions based on their requested access permissions.
If anyone has entered a recovery phrase or private key into any of these extensions, the Socket team advises treating the wallet as "permanently compromised" and moving funds to a new wallet, as uninstalling an extension does not retract any phrases already transmitted elsewhere.
Browser extensions have increasingly become a common method for cryptocurrency theft, with a recently uncovered Chrome extension having siphoned fees from Solana traders for an extended period before detection, while attackers have also embedded stealers in pirated software, a counterfeit Mac clipboard app, and PC games distributed via Steam.