Socket identified 40 malicious Firefox extensions capable of capturing recovery phrases, private keys, credentials, and internal data from cryptocurrency wallets. The discovery is part of a larger operation, with 77 related extension identities, detailed by the security company in a report published on August 19.
Of the 77 tracked extensions, another 37 were classified as deceptive or suspicious, but the analyzed versions did not contain confirmed code for stealing credentials or assets. They presented themselves as tools for various functions, although in practice they ran sports scoreboard applications.
The campaign, provisionally called by Socket “Offside Wallet Theft Factory”, has been operating since at least March 2026. Mozilla signature records analyzed by the company range from March 9 to August 3, with peak activity in April and late July.
The investigation found extensions that imitated products such as OKX, Rabby Wallet, and TronLink, as well as versions that used names similar to the originals with visually similar characters. Socket states that the set shows code reuse, infrastructure, publishing patterns, and similar update histories, although it is still not possible to state that all extensions were controlled by a single group.
Attacks used four different methods
Among the 40 extensions confirmed as malicious, seven functioned as loaders for remotely controlled phishing pages via Supabase projects. The infrastructure allowed operators to change the content shown by the extension without needing to publish a new version in Firefox.
One of the analyzed cases was 0KX WEB3, which imitated the OKX wallet by replacing the letter “O” with a zero. The extension appeared in the Firefox store as a Web3 wallet, but had no real functions to create wallets, manage keys, check balances, or make transfers.
Instead, it contained a notepad used as a disguise and remotely fetched a page configured by the operators. That page presented options to create or import a wallet and requested recovery phrases of up to 24 words or private keys.
Socket observed that 0KX WEB3 had seven users while it was still available. The extension was reported to Mozilla and removed before the publication of the investigation.
Another group of 15 extensions kept the fake interface and the theft code directly inside the signed packages for Firefox. Captured data was sent to Cloudflare Workers instances controlled by the operators.
Some of these extensions reused modified code from Rabby Wallet. The software was able to continue functioning as an apparently normal wallet, but intercepted recovery phrases of 12 or 24 words during account creation or import and sent the data to external servers.
Extensions could copy data before encryption
Socket also found 13 modified versions of Rabby Wallet that attacked a different internal stage. They intercepted so-called keyrings — structures that store information used to manage a wallet’s accounts — before that data was encrypted locally.
In Rabby’s legitimate operation, keyrings are serialized, encrypted, and then stored on the device. In the modified extensions, the code sent the still-unencrypted version to an external address before completing the normal process.
This allowed the wallet to keep functioning without showing an obvious error to the user. According to the analysis, eight of the 13 variants had virtually the entire package identical, with changes concentrated mainly in the addresses used to receive the stolen data.
Another five extensions extended the attack beyond wallets and collected credentials and clipboard content. The data was transmitted to the same command-and-control infrastructure, located at a fixed IP address.
Depending on what was copied by the user, the clipboard could expose passwords, authentication information, cryptocurrency addresses, private keys, or other sensitive data.
Scoreboard extensions were repurposed as malware
One of the elements that helped Socket link different parts of the operation was the extensions’ version history. Nine identities that later distributed malware had previously been used for sports scoreboard applications.
These earlier versions showed soccer, basketball, NBA, or American football results. Later, new updates kept the same identity in Firefox but replaced the sports function with code aimed at wallet theft.
Socket found, for example, an extension called Quick Shield, which worked as a basketball results app and later, under the same identity, began distributing a version that imitated Rabby and stole internal wallet data. Similar cases occurred with extensions initially associated with NBA and American football scoreboards.
The other 37 suspicious extensions analyzed by the company follow a related pattern. They advertised functions such as VPN, currency conversion, screenshot capture, password generation, and dark mode, but ran sports scoreboard applications.
Thirty-two shared virtually the same implementation to fetch soccer results, while another five looked up basketball, NBA, and hockey information. All reused the same embedded credential for legitimate API-Sports services.
Socket did not find in these 37 versions confirmed code for stealing wallets, credentials, or clipboard data. Even so, it classified the group as deceptive and suspicious due to the version history, publication patterns, and relationship with extensions that later came to distribute malware.
Removing the extension does not invalidate an already exposed key
The main consequence for affected users is that uninstalling an extension does not make a recovery phrase or private key that has already been transmitted safe.
A recovery phrase allows reconstructing a wallet’s keys on another device. Therefore, Socket recommends that users who have provided this data to one of the affected extensions transfer their remaining assets to a new wallet created with a new recovery phrase.
The same applies to cases where an extension managed to transmit the keyrings before encryption. For users exposed only to variants that collected credentials and clipboard content, the recommendation includes changing affected passwords, closing open sessions, and verifying previously copied destination addresses.
The investigation also shows that apparently limited permissions are not enough to determine whether an extension is safe. Some malicious variants only needed to load an external interface and convince the user to enter their secret information.
Socket documented the infrastructure, the exfiltration methods, and the ability of the extensions to compromise wallets, but has not identified so far a confirmed number of victims, transactions attributable to the campaign, or a total loss amount.



