77 Firefox Add-ons Caught Running a Coordinated Crypto Wallet Heist
Forty Firefox browser extensions have been confirmed as malicious after researchers caught them impersonating well-known Web3 products including OKX, Rabby Wallet, and TronLink. Their actual job: siphoning cryptocurrency wallet secrets from anyone unfortunate enough to install them.
The discovery comes from Socket's Threat Research team, who identified a wider cluster of 77 extensions sharing code, infrastructure, and what security researcher Kirill Boychenko diplomatically describes as "malicious intent." The campaign, which researchers have named Offside Wallet Theft Factory, appears to have been running since March 2026. Nobody has pinned it to a known threat group yet.
Of the 40 confirmed bad actors, the breakdown is fairly grim. Seven use attacker-controlled Supabase projects as remote kill switches to serve phishing or decoy content on demand. Fifteen are designed to hoover up recovery phrases and private keys, pushing the stolen data out through Cloudflare Workers. Thirteen are doctored Rabby Wallet builds that grab serialized keyrings before local encryption gets a chance to protect them. The remaining five stick to hard-coded command-and-control servers to harvest credentials and clipboard contents.
The theft happens via two approaches. Some extensions remotely load a fake wallet interface. Others have the malicious functionality baked directly into the extension code itself. Either way, the user sees something that looks legitimate while their secrets go elsewhere.
There's a particularly cynical wrinkle here. Several of the extensions originally appeared on the official Firefox Add-ons marketplace looking completely harmless, posing as sports score trackers or generic utility tools. Once established under a legitimate Firefox extension ID, the operators quietly repurposed them into wallet-stealing malware. Nine of the confirmed malicious extensions went through exactly this conversion, graduating from football scores to financial theft under the same identity.
The remaining 37 extensions in the broader cluster haven't been confirmed as actively stealing wallets yet, but they share hard-coded credentials for API-Sports, a real-time sports data service, while advertising completely unrelated features like VPN access, dark mode, currency conversion, and note-taking. That's not the behaviour of extensions with clean intentions.
Some of the confirmed malicious extension names include Rabbit For Desktop, RABB-Wallet Web3 & EVM, and Rabbit/WALLET - EVM, with various deliberate misspellings and Unicode character substitutions designed to pass casual inspection.
Boychenko puts the economics of this bluntly: one successful installation can expose a recovery phrase or private key worth far more than the trivial cost of repeatedly publishing throwaway extensions. Rotating names, cloning code, splitting malicious functionality across multiple components, and leaning on cloud infrastructure makes this kind of campaign cheap to run and easy to scale, even when individual extensions get pulled down.
The practical advice here is depressingly simple: if you're managing crypto wallets, install extensions only from sources you have strong reason to trust, verify publisher details carefully, and treat anything mimicking a popular wallet brand with serious suspicion. The Firefox Add-ons marketplace is not the safe harbour it might appear to be.