
Security firm uncovers 'Offside Wallet Theft Factory' campaign affecting 40 Firefox extensions
AI-generated summary
Socket identified 40 malicious Firefox add-ons that exfiltrate crypto wallet secrets. The campaign operated from March to August 2024.
Software supply-chain security firm Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto, including nine that had previously distributed sports-score tools under the same IDs.
Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions must treat that wallet as compromised because uninstalling the add-on cannot revoke an exposed secret.
The Aug. 19 report linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious behavior. The other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload.
The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July.
Socket’s version histories show that the nine affected IDs were:
Firefox ID: [email protected] | Earlier sports version: Quick Quick 7.4.0 | Later malicious version: Rabbit For Desktop 8.20.10 Firefox ID: [email protected] | Earlier sports version: Dial Open Pro 7.23.25 | Later malicious version: Web3 & EVM 9.50.10 Firefox ID: [email protected] | Earlier sports version: Quick Shield 5.7.1 | Later malicious version: Rby-WALLEТ 6.7.10 Firefox ID: [email protected] | Earlier sports version: Lite Swatch 6.5.21 | Later malicious version: 🐇abby-WALLEТ 7.10.10 Firefox ID: [email protected] | Earlier sports version: Key Pulse 8.1.21 | Later malicious version: RABB-Walleť 8.22.30 Firefox ID: [email protected] | Earlier sports version: Timer Pulse 5.5.5 | Later malicious version: Rabbit WALLЕТ 11.10.10 Firefox ID: [email protected] | Earlier sports version: Track Quick 6.10.24 | Later malicious version: RabbWALLЕТ 7.10.30/8.10.30 Firefox ID: [email protected] | Earlier sports version: Store Plus 8.3.18 | Later malicious version: Rabb🐇WALLЕТ 9.11.30 Firefox ID: [email protected] | Earlier sports version: Pomodoro Plus 9.13.24 | Later malicious version: RABB-WALLEТ 10.20.10
Socket said several campaign add-ons were still live when it reported them to Mozilla. Its report noted that the remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication.
What affected crypto users should do
The 40 malicious identities used distinct attack paths. Seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data.
A recovery phrase or private key can restore a wallet elsewhere, and a serialized keyring similarly exposes the wallet’s account state before encryption can protect it.
Anyone who entered one of those secrets, or used an affected build that transmitted its keyring, should move remaining assets to a fresh crypto wallet created from a new recovery phrase.
Users exposed only to the credential-and-clipboard group should change affected passwords, terminate active sessions where possible, and verify copied destination addresses. Wallet keys need rotation when wallet-secret or keyring exposure occurred.
Mozilla says it uses automated risk indicators and human review to identify malicious wallet add-ons, and advises users to install only extensions linked from the wallet provider’s official site.
Socket documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a campaign loss total.

Trail of Bits identified a security flaw in Provenance Blockchain affecting 82 asset accounts. The bug allowed unauthorized administrative control and minting due to a supply record mismatch. Patches were released in May and June to remediate the vulnerability.

Security firm Socket has uncovered a campaign dubbed 'Offside Wallet Theft Factory,' where 77 Firefox extensions were used to steal crypto wallet recovery phrases. The malicious add-ons impersonated popular wallets like OKX and Rabby, with some masquerading as sports apps.

Galaxy Research reports that 87.3% of the 1,789.28 Bitcoin (worth $114.7M) stolen in the Coldcard hack remains unmoved, with most funds still in attacker-controlled addresses.

Shipyard, a key maintainer of the InterPlanetary File System (IPFS), will end engineering and infrastructure operations on September 30 after Protocol Labs declined to renew funding, leaving several IPFS projects without dedicated support.

Ledger has released Ethereum app version 1.22.2 to patch a vulnerability that allowed malicious dApps to replace transaction data during signing. The flaw, identified by TestMachine and Ledger Donjon, affects multiple models including Ledger Flex, Nano X, and Stax.

BNB Smart Chain has launched its Pasteur hard fork, an upgrade designed to improve network security, bridge verification, and block capacity. The update integrates three BNB Evolution Proposals to streamline transaction processing and validator operations.