Fake Firefox Wallet Extensions Drain Crypto From Unwary Users

Researchers at Socket found 40 Firefox add-ons impersonating OKX, Rabby, TronLink and other crypto wallet brands, part of a wider 77-extension operation they call Offside Wallet Theft Factory.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal overhead shot of a dark desk with a laptop screen showing an abstract browser extensions management interface, glowing slightl
Share

Key points

  • Socket's Threat Research team identified 40 malicious Firefox extensions posing as legitimate crypto wallet tools.
  • The 40 add-ons sit inside a larger cluster of 77 extensions that share code and back-end servers.
  • Impersonated brands include OKX, Rabby Wallet and TronLink, all widely used Web3 products.
  • Socket has named the operation the Offside Wallet Theft Factory.
  • Users who installed any of the fakes should assume their wallet seed phrases are exposed and move funds to a fresh wallet.

Security researchers have flagged 40 Firefox browser add-ons that pretend to be well-known cryptocurrency wallet tools but are built to steal the secrets that unlock those wallets.

The find comes from the Socket Threat Research team, who say the 40 extensions are part of a wider group of 77 add-ons running on shared code and shared servers. Socket calls the operation the Offside Wallet Theft Factory. The Hacker News reported the findings first.

What are these extensions pretending to be?

They pretend to be crypto wallet software. A crypto wallet is the app that holds the digital keys to someone's cryptocurrency. Lose the keys, lose the money.

The fakes copy the names and looks of established Web3 brands, including OKX, Rabby Wallet and TronLink. Web3 is the umbrella term for apps built on blockchain networks, the shared digital ledgers behind cryptocurrencies like Bitcoin and Ethereum. Someone searching the Firefox add-on store for a familiar wallet name could easily install one of the fakes by mistake.

Once installed, the extension behaves enough like the real product to seem normal. Behind the scenes, it captures the wallet's seed phrase or private keys, the string of words or characters that gives full control of the funds, and sends them to the attackers.

Who is behind the campaign?

Socket has not publicly attributed the campaign to a named group. What the researchers can say is that the 77 add-ons share source code fragments and connect to overlapping infrastructure, meaning the same servers and domains crop up across supposedly unrelated extensions. That pattern points to a single operator or a small team running the whole factory.

The name Offside Wallet Theft Factory reflects the industrial scale of it. This is not one bad extension slipping through. It is a production line.

What should Firefox users do?

If you installed any wallet extension recently, check it. Open Firefox, go to Add-ons and themes, and look at the publisher name and reviews. A legitimate OKX, Rabby or TronLink extension will link to the official project site and have a long review history. A fake often has a thin review count, a recent publish date, or an odd publisher handle.

If anything looks off, remove the extension straight away. Then assume the wallet is compromised. Set up a brand new wallet in a clean browser profile or on a hardware wallet, a small physical device that stores keys offline, and move your funds there. Do not reuse the old seed phrase.

Browser add-on stores have become a favourite delivery route for crypto theft because installing an extension feels routine and the permissions prompt is easy to click past. Mozilla removes malicious extensions when they are reported, but takedowns typically come after victims have already lost money.

Common questions

How do I know if my wallet has been drained?

Check the wallet's transaction history through a blockchain explorer for the network you use, such as Etherscan for Ethereum. Any transfers you did not authorise are the sign. Contact the real wallet provider's support channel if you need help reading the history.

Are Chrome or Edge users affected?

Socket's report names Firefox add-ons. Similar campaigns have targeted Chrome and Edge in the past, so the sensible move is to audit wallet extensions on every browser you use, not just Firefox.

© 2026 Threat Vectr