Breaking
RUВСУ атаковали Луганск более чем 30 ударными БПЛАRURussian Defense Ministry reports interception of 426 Ukrainian drones overnightTRLyon - Fenerbahçe maçı ne zaman, saat kaçta, hangi kanalda? Muhtemel 11'lerINTLFlash floods cause casualties and destruction in Nepal and TibetESIncendio en hospital de Islamabad deja al menos 14 bebés fallecidosCN俄羅斯阿穆爾氣體化工廠火災:6名中國公民罹難,9人失聯ARمظلوم عبدي يعلن حل قوات سوريا الديمقراطية كقوة مستقلة واندماجها في مؤسسات الدولة السوريةGLOBALUK faces flood risk as Met Office issues thunderstorm warningsITCaro carburanti: prezzi in salita e attesa per il Consiglio dei ministriEUMillions at risk as El Niño-fuelled wildfires blanket Indonesia in thick hazeRUВСУ атаковали Луганск более чем 30 ударными БПЛАRURussian Defense Ministry reports interception of 426 Ukrainian drones overnightTRLyon - Fenerbahçe maçı ne zaman, saat kaçta, hangi kanalda? Muhtemel 11'lerINTLFlash floods cause casualties and destruction in Nepal and TibetESIncendio en hospital de Islamabad deja al menos 14 bebés fallecidosCN俄羅斯阿穆爾氣體化工廠火災:6名中國公民罹難,9人失聯ARمظلوم عبدي يعلن حل قوات سوريا الديمقراطية كقوة مستقلة واندماجها في مؤسسات الدولة السوريةGLOBALUK faces flood risk as Met Office issues thunderstorm warningsITCaro carburanti: prezzi in salita e attesa per il Consiglio dei ministriEUMillions at risk as El Niño-fuelled wildfires blanket Indonesia in thick haze
BackSecurity firm Socket identifies 'Offside Wallet Theft Factory' campaign targeting Firefox users
Security firm Socket identifies 'Offside Wallet Theft Factory' campaign targeting Firefox users
Urgent
Decrypt42 minutes agoTech2 min read

Security firm Socket identifies 'Offside Wallet Theft Factory' campaign targeting Firefox users

Malicious extensions impersonating crypto wallets like OKX and Rabby were found to be harvesting recovery phrases from users.

Quick Look

  • Security firm Socket has uncovered a campaign dubbed 'Offside Wallet Theft Factory,' where 77 Firefox extensions were used to steal crypto wallet recovery phrases.
  • The malicious add-ons impersonated popular wallets like OKX and Rabby, with some masquerading as sports apps.

AI-generated summary

Why It Matters

Socket's research team linked 77 Firefox extension identities through shared code and infrastructure. The campaign operated from March 9 to August 3.

Font size

Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious.

They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.

Nine were published as sports-score apps before later versions replaced that function with wallet-stealing code.

Firefox users have been targeted by a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases.

Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious. Mozilla signing records place the campaign from March 9 to August 3, with several extensions still live when Socket reported them.

The malicious add-ons impersonate OKX, Rabby Wallet, TronLink and other Web3 products, often using characters that resemble the real names closely enough to pass a glance. Roughly half present a convincing wallet interface and ask the user to import an existing wallet, harvesting whatever recovery phrase or private key gets typed in. Another 13 are modified builds of Rabby that behave normally while sending the wallet's stored account data to an outside server as it is saved. Five collect saved credentials and clipboard contents instead.

From football scores to wallet theft

A further 37 identities are dressed as password generators, dark mode toggles, VPNs, currency converters and note-taking tools, but actually run live sports-score applications, all sharing a single hardcoded credential for a legitimate sports data provider.

Nine confirmed malicious extensions started the same way, publishing football, basketball, NBA or American football score apps under the same Firefox IDs before later updates replaced that code with wallet stealers, inheriting whatever install base and review history the original had built. Socket named the campaign the Offside Wallet Theft Factory after the pattern, while cautioning that it has not established a single operator behind every extension.

One counterfeit OKX wallet asked for only two permissions, storage and tabs, because it never needed to search the browser for anything. It simply loaded a remote page and waited for the user to enter a recovery phrase, which Socket flags as a limit of judging extensions by the access they request.

Anyone who entered a recovery phrase or private key into one of these should treat it as "permanently compromised" and move funds to a new wallet, the Socket team said, since uninstalling an extension does not revoke a phrase already sent elsewhere.

Open Questions

  • Who is the operator behind the Offside Wallet Theft Factory?
  • How many users were affected by the theft?

Related Topics

This article was originally published by Decrypt.

Related Stories

More on this topicfirefox