Socket Threat Research has uncovered 40 Firefox extensions quietly siphoning cryptocurrency wallet secrets. The add-ons pose as OKX, Rabby Wallet, TronLink, and other Web3 products on Mozilla’s official storefront.
The add-ons are part of a broader set of 77 extensions sharing source code and infrastructure, in a campaign dubbed Offside Wallet Theft Factory that has been active since March 2026. The activity is not attributed to any known group.
Fifteen of the extensions capture recovery phrases and private keys, exfiltrating them through Cloudflare Workers. Thirteen are modified Rabby Wallet builds that siphon serialized keyrings before local encryption. Seven use attacker-controlled Supabase projects as remote switches to serve phishing or decoy content, and the remaining five grab credentials and clipboard data through hard-coded command-and-control infrastructure.
The other 37 extensions form a coordinated sports score operation across football, basketball, and hockey that contains no confirmed stealing payloads but shows deceptive functionality and shared publishing artifacts. Some add-ons first appeared on the official Firefox marketplace as score or utility shells, then flipped into wallet stealers under the same Firefox ID.
The theft works two ways: some extensions load a counterfeit wallet page from a remote server, while others embed the stealing logic directly in the add-on itself.
Users should audit installed add-ons, remove anything unfamiliar, and never enter wallet recovery phrases into browser extensions.
