40 fake Firefox crypto wallets, plus a important key-rotation warning
Socket researchers found 40 malicious Firefox add-ons draining crypto wallets, and nine of them started as harmless sports-score tools before pivoting to theft. If your recovery phrase touched these extensions, your wallet is compromised even after uninstalling them.
A new report from software supply-chain security firm Socket has exposed a coordinated malware campaign targeting Firefox users, and the scale is bigger than most people realize. The firm linked 77 add-on identities to what it's calling the "Offside Wallet Theft Factory," with 40 showing confirmed malicious behavior. Nine of those 40 were particularly sneaky: they operated under the same identity as earlier sports-score tools before a routine update swapped in wallet-draining code.
The campaign ran from at least March through August, with Mozilla signing records clustering around April and late July. That's a long window for this kind of thing to stay live. Socket's version histories show 15 of the malicious identities were capturing recovery phrases, private keys, and other wallet secrets, while 13 more were modified clones of Rabby wallet that sent serialized keyrings away before local encryption could protect them. Seven were remote-controlled phishing loaders, and five collected credentials and clipboard data.
Here's the part that should worry anyone who touched these. Uninstalling the add-on doesn't matter. If your recovery phrase or private key passed through one of those malicious versions, that wallet is compromised, period. A serialized keyring exposes the account state before encryption kicks in, which means someone else can reconstruct it. Socket found no confirmed victims or total loss figures, but that's cold comfort when the exfiltration infrastructure was already documented.
Mozilla says it uses automated risk indicators and human review to catch these, and the report notes that the 0KX WEB3 phishing add-on was still live with seven users during analysis. Mozilla removed it before publication. So this isn't a solved problem, and it's not even a Firefox-specific one. Chrome has seen similar wallet-stealing extensions climb the rankings.
Under neutral conditions, I'd tell you to be careful about permissions. But this is a bit more serious than that. The smartest move is to rotate keys and move assets to a fresh wallet with a brand new recovery phrase if you suspect any exposure. This is how the smart money is positioned: no shortcuts, no trust in a simple uninstall. The supply chain has become the attack surface.
What's next? Watch whether Mozilla tightens its review process or starts requiring manual code review for wallet-connected extensions. Because the bad actors already proved they can hide in plain sight with a sports scoreboard.
Explore More
Key Terms Explained
A social engineering attack where scammers create fake websites, emails, or messages that look legitimate to steal your credentials or trick you into signing malicious transactions.
A secret code that gives you control over your cryptocurrency.
Wallets belonging to successful traders, VCs, or insiders who consistently make profitable moves.
Software or hardware that stores your cryptocurrency private keys and lets you send and receive tokens.