40 Firefox Extensions Found Stealing Web3 Wallets

Security researchers have uncovered a widespread campaign targeting Web3 users through malicious Firefox extensions. A total of 40 add-ons were confirmed to be actively stealing cryptocurrency wallet credentials by posing as trusted tools like OKX, TronLink, and Rabby Wallet. Under the campaign name “Offside Wallet Theft Factory,” these extensions are just one part of a larger set of 77 add-ons sharing overlapping code and infrastructure. These findings date back to March 2026. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

What These Extensions Do

The 40 confirmed malicious extensions employ several different methods to steal wallet secrets. Some use remote switches powered by actor-controlled Supabase projects to dynamically load phishing or decoy wallet content. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) Others—about 15 of the 40—capture sensitive data like private keys and recovery phrases and send them via Cloudflare Workers. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) A block of 13 builds masquerade as modified versions of Rabby Wallet, exfiltrating serialized keyrings before local encryption. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) The rest capture credentials and clipboard data using hard-coded command-and-control servers. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

Deceptive Disguises & Progression

Many of these extensions started out harmless in appearance—listing themselves in the Firefox Add-ons marketplace under innocent guises like VPN tools, screenshot capture utilities, dark mode switchers, note-taking apps, or sports score trackers. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) Over time, some were updated under the same Firefox IDs to include wallet-stealing capabilities. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) One subgroup of 37 extensions operated as “sports score shells,” fake sporting add-ons that visible to users, while hidden malicious features lay dormant until later updates. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

The sports score shells inflated cover stories—including using real sports APIs like API-Sports—to seem legitimate, offering features from basketball scores to VPN promises. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) As of historical version analysis, nine identities in the malicious set first acted purely as sports-score apps, later morphing into full-fledged wallet stealers. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

Attack Scale & Identity Tactics

The campaign is large-scale: the 77-add-on arsenal includes 40 confirmed wallet stealers and 37 more with heavy signs of coordinated fraud, even if not conclusively malicious. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html)) It appears threat actors have been rotating extension names and IDs, reusing identities, and splitting malicious code across extensions and external infrastructure to stay ahead of detection. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

Some of the names are openly fraudulent—variations of “Rabby Wallet,” “Rabbit Wallet,” or “CryptoPortfolio” among others. Single installs can yield wallet recovery phrases or private keys, which often are much more valuable to attackers than the cost of creating and publishing these extensions. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

It’s not yet known who is behind the campaign. No confirmed attribution has been made public. ([thehackernews.com](https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html))

What Users Should Do: Web3 users should audit their Firefox extensions and remove anything unfamiliar—especially apps claiming to be wallets or utilities. Enabling two-factor authentication, using hardware wallets, and keeping recovery phrases offline will reduce risk. Browser vendors need to strengthen review processes in their extension stores to catch deceptive functionality earlier.

The rise of these fake Web3 extensions underlines how attackers are blending into legitimate tools to exploit trust, especially as demand for wallet integrations and crypto interfaces remains high. This campaign shows that malicious extensions aren’t just aimless spyware—they’re increasingly sophisticated fraud operations. The broader lesson: when security is treating extensions as a peripheral risk, users and browser platforms must shift gears. Expect ongoing evolution—both in the tactics of extension-based malware and in defenses from Mozilla and others. Prioritize verifying authenticity and understanding permissions before trusting anything in your browser environment.