40 Firefox Add-Ons Targeted Crypto Wallets; 9 Were Sports Tools

Security firm Socket found 40 Firefox extension IDs that switched to wallet‑stealing behavior; nine began as sports‑score tools. Exposed wallet secrets remain compromised after uninstall.

Socket, a software supply-chain security firm, reported on Aug. 19 that it identified 77 Firefox extension identities linked to an operation it calls the “Offside Wallet Theft Factory.” Of those, 40 contained code or infrastructure tied to wallet theft, phishing or credential capture. The remaining 37 appeared as sports‑score shells in the analyzed builds with no confirmed theft payload.

Mozilla signing records for the versions Socket reviewed run from March 9 through Aug. 3, with activity concentrated in April and late July. Socket’s timeline shows the campaign operated at least from March into August.

The malicious extensions used several attack methods. Socket identified seven remote‑controlled phishing loaders, 15 builds that captured recovery phrases or private keys, 13 modified clones of a popular wallet extension that transmitted serialized keyrings off the device before local encryption, and five builds that harvested passwords and clipboard contents. Because a recovery phrase, private key or an unencrypted serialized keyring can restore a wallet on another device, removal of an extension does not revoke those exposed secrets.

Socket mapped nine extension IDs that originally distributed sports‑score tools and later appeared in builds that targeted wallets. The report includes examples of IDs that moved from sports‑score names to variants with wallet‑related names.

Several infected add-ons remained live when Socket reported them to Mozilla. One remote‑controlled phishing extension, identified in the report as 0KX WEB3, had seven users and was removed by Mozilla before the findings were published. Mozilla uses automated risk indicators and human review to flag malicious wallet extensions and recommends installing wallet add-ons only from official provider sites.

Socket’s report advises that anyone who entered a recovery phrase, private key or whose wallet keyring was transmitted must treat the wallet as compromised and move remaining assets to a new wallet created with a fresh recovery phrase. For users exposed only to credential‑ and clipboard‑harvesting builds, the guidance calls for changing affected passwords, ending active sessions where possible, and verifying copied destination addresses before sending funds. Wallet key rotation is required when wallet secrets or keyrings have been exposed.

The report documents theft capability and exfiltration infrastructure but does not identify confirmed victims, attributable transactions or a total loss figure tied to the campaign. Socket and browser vendors continue to monitor extension signing and distribution channels for similar activity.

Articles by this author