Hacking

Firefox Wallet-Stealing Extensions Target Crypto Users

Published  ·  5 min read

If you’re using Firefox and have added crypto wallet extensions on your browser, then pay attention. Security researchers just uncovered a major operation which has been secretly stealing people’s cryptocurrencies since March 2026.

The campaign, called Offside Wallet Theft Factory, uses 40 malicious Firefox extensions that look just like legitimate Web3 products. They pretend to be OKX, Rabby Wallet, TronLink, and other popular crypto tools. In fact, rather than helping you manage your funds, their intention is to steal from you not only your recovery phrases but also any other information that will enable them to drain your wallet.

Here's what's happening and how you can protect yourself.

What's Going On?

Security researchers at Socket Threat Research found 77 suspicious Firefox extensions. Out of those, 40 are confirmed malicious. The other 37 are part of a coordinated decoy operation using sports score shells.

The Numbers:

  • 40 malicious extensions identified
  • 77 total extensions associated with the campaign
  • In operation since March 2026
  • Pretending to be OKX, Rabby Wallet, and TronLink

How Do These Extensions Steal Your Crypto?

Here are four methods through which these extensions steal your wallet data:

Method 1: Remote Phishing Pages

Seven extensions connected to attacker-controlled Supabase projects. They worked as remote switches, the extension had the ability to adapt its behavior according to the circumstances and could present either valid content or the phishing page.

Method 2: Direct Steal from the Wallet

Fifteen extensions directly stole recovery phrases, private keys, and other secrets related to wallets. All this data was passed via Cloudflare Workers, making the theft harder to trace.

Method 3: Modified Rabby Wallet Builds

Thirteen extensions were actually modified versions of Rabby Wallet. They grabbed serialized keyrings before local encryption could protect them.

Method 4: Hard-Coded C2

Five extensions used hard-coded command-and-control infrastructure to steal credentials and clipboard data.

The Sports Score Shell Trick

This is where it gets sneaky. The attackers didn't just publish malicious extensions right away. They played the long game.

Step 1: They published sports score extensions.

These looked harmless. They showed football, basketball, NBA, and hockey scores. Moreover, there were additional features such as:

  • Password generator
  • Dark mode
  • VPN capability
  • Currency converter
  • Screenshot capturing
  • Note-taking

Step 2: Establishing trust.

The extensions got approved. People installed them. Some even left reviews.

Step 3: They repurposed them.

Once the extensions were established, the attackers turned them into wallet-stealing malware. They kept the same Firefox ID, so it looked like the same extension.

Which Extensions Should You Watch For?

Here are some of the malicious extensions identified:

Extension Name

ID

Safe-Themes - Browser Extension

[email protected]

Rabbit For Desktop

[email protected]

aby WaIet

[email protected]

Rabb-Walӏet CryptoPortfolio

[email protected]

RABB-Walӏet Web3 & EVM

[email protected]

Rabbit/WALLET - EVM

[email protected]


What to Look For:

Extensions with "Rabbit" or "Rabb" in the name are a red flag. The attackers used these to mimic legitimate wallets.

Why This Campaign Is So Dangerous

The economics of this operation make it easy for attackers to keep going.

The Math:

One successful installation can expose a recovery phrase worth far more than the cost of publishing a disposable extension. And since Firefox extensions are cheap to publish, the attackers can keep rotating names and IDs.

The Researcher's Take:

"A single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions," said Kirill Boychenko of Socket Threat Research.

The Scaling:

"Rotating names and IDs, repurposing existing extension identities, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure make repeated publication cheap and scalable."

What You Should Do Right Now

1. Check Your Installed Extensions

Open Firefox and look at your extensions. Do you recognize all of them? Whenever you find anything that has “Rabbit” or “Rabb” in it, take action.

2. Delete Anything Suspicious

Delete all extensions that you do not know about immediately. All extensions that are not in use regularly must be removed.

3. Secure Your Wallets

If you feel like you might have installed any such extension, then do the following:

  • Transfer your money to new wallets.
  • Generate new recovery phrases.
  • Create new passwords.

4. Take Precautions in Future

  • Install only those extensions that have been developed by trustworthy sources.
  • Read the permissions before installing.
  • Check for reviews and ratings.

Conclusion

The Offside Wallet Theft Factory, which is a huge operation, has been stealing cryptos using 40 Firefox extensions since March 2026. These Firefox extensions look like OKX, Rabby Wallet, and TronLink. They use the sports score shells as their disguise.

What You Should Know:

  • 40 malicious extensions have been deployed
  • The operation began in March 2026
  • Wallets, private keys, and recovery phrases were stolen
  • Disguised by means of the sports score shells

What You Can Do About It:

  • Review your Firefox extensions
  • Remove suspicious extensions
  • Protect your wallets
  • Download from trusted sources only

FAQ Section

What is Offside Wallet Theft Factory?

This is an operation where attackers steal crypto wallet data by using malicious Firefox extensions. The malicious Firefox extensions disguise themselves to be actual Web3 applications such as OKX, Rabby Wallet, and TronLink.

How many malicious extensions were found?

Forty malicious extensions were found. Another 37 extensions are part of a sports score shell decoy operation.

How do the extensions steal data?

They leverage phishing sites, wallet builds with modifications, and C2 architecture that is hard coded to get recovery phrases, private keys, and clipboards.

What can Firefox users do?

Check installed browser add-ons, delete potentially malicious ones, and protect your wallets. Use add-ons developed only by trustworthy developers.

Who is behind the campaign?

It is yet unclear what cybercriminals were behind this campaign.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067