Fake Firefox Wallet Extensions Drain Crypto From Unwary Users

Researchers at Socket found 40 Firefox add-ons impersonating OKX, Rabby, TronLink and other crypto wallet brands, part of a wider 77-extension operation they call Offside Wallet Theft Factory.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A Firefox browser window displaying the extensions panel with multiple wallet extension icons visible, some appearing nearly identical, with warning flags overl
Share

Key points

  • Socket's Threat Research team identified 40 malicious Firefox extensions posing as legitimate crypto wallet tools.
  • The 40 add-ons sit inside a larger cluster of 77 extensions that share code and back-end servers.
  • Impersonated brands include OKX and Rabby Wallet, plus TronLink and other Web3 products.
  • Socket has named the operation the Offside Wallet Theft Factory.
  • Users who installed any of the fakes should assume their wallet seed phrases are exposed and move funds to a fresh wallet.

Security researchers have flagged 40 Firefox browser add-ons that pretend to be well-known cryptocurrency wallet tools but are built to steal the secrets controlling those wallets.

The find comes from the Socket Threat Research team, who say the 40 extensions are part of a wider group of 77 add-ons running on shared code and shared servers. Socket calls the operation the Offside Wallet Theft Factory. The Hacker News reported the findings first. It's the kind of campaign our August coverage of Firefox's signing-key exposure hinted at: the add-on store is a soft target, and attackers know it.

What are these extensions pretending to be?

They copy the names and appearances of established Web3 brands, OKX, Rabby Wallet, and others including TronLink. Web3 is the umbrella term for apps built on blockchain networks, the shared digital ledgers behind cryptocurrencies like Bitcoin and Ethereum. A crypto wallet holds the digital keys to someone's funds: lose the keys, lose the money. Someone searching the Firefox add-on store for a familiar wallet name could easily install one of the fakes by mistake.

Once installed, the extension behaves enough like the real product to seem normal. Behind the scenes it captures the wallet's seed phrase or private keys, the string of words or characters that gives full control of the funds, and sends them to the attackers.

Who is behind the campaign?

Socket hasn't publicly attributed the campaign to a named group. What the researchers can say is that the 77 add-ons share source code fragments and connect to overlapping infrastructure, meaning the same servers and domains appear across supposedly unrelated extensions. That pattern points to a single operator or a small team running the whole factory.

This isn't one bad extension slipping through. It's a production line, and the name Offside Wallet Theft Factory reflects that scale.

What should Firefox users do?

If you installed any wallet extension recently, check it now. Open Firefox, go to Add-ons and themes, and look at the publisher name and reviews. A legitimate extension will link to the official project site and carry a long review history. Fakes often show a thin review count, a very recent publish date, or a strange publisher handle.

If anything looks off, remove the extension immediately. Then treat the wallet as compromised. Set up a brand new wallet in a clean browser profile or on a hardware wallet, a small physical device that stores keys offline, and move your funds there. Don't reuse the old seed phrase.

Browser add-on stores have become a favoured delivery route for crypto theft because installing an extension feels routine and the permissions prompt is easy to click past. Mozilla removes malicious extensions when they're reported, but takedowns typically come after victims have already lost money. Worth watching: whether Mozilla tightens publisher verification requirements in response, given that Firefox 154 already needed 58 security patches just last month.

Common questions

How do I know if my wallet has been drained?

Check the wallet's transaction history through a blockchain explorer for the network you use, such as Etherscan for Ethereum. Any transfers you didn't authorise are the signal. Contact the real wallet provider's support channel if you need help reading the history.

Are Chrome or Edge users affected?

Socket's report names Firefox add-ons. Similar campaigns have hit Chrome and Edge before, so audit wallet extensions on every browser you use, not just Firefox.

© 2026 Threat Vectr