Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
In brief Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious. They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.

Why It Matters
This story touches on dozens, fake, firefox — topics readers are actively tracking. Review and add editorial context before publishing.
Key Facts
- Fact 1: In brief Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious.
- Fact 2: Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious.
- Fact 3: Mozilla signing records place the campaign from March 9 to August 3, with several extensions still live when Socket reported them.
- Fact 4: Socket Threat Research uncovered a 77-extension Firefox campaign: 40 steal wallet secrets and credentials.
In brief Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious. They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.
Nine were published as sports-score apps before later versions replaced that function with wallet-stealing code. Firefox users have been targeted by a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases. Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious.
(Original synthesis pending human/AI review — generated by the stub provider by selecting real sentences from the source material, not by writing new analysis or commentary.)
Original source: Decrypt
Related Stories

South Korea trade giant POSCO brings trade receivables to Avalanche in latest tokenization move
Term Finance Permanently Shuts Meta Vaults After Exploit PeckShield Estimated at $8.5 Million

Mistral and HUMAIN Are Building 'Sovereign AI' in Saudi Arabia
