Firefox has become the target of an elaborate campaign of malicious browser extensions that extract crypto wallet secrets from unsuspecting users. Disguised as legitimate tools—wallets, themes, notepads—these add-ons collect recovery phrases, private keys, login info, and clipboard content before exfiltrating them via cloud infrastructure. The fraud ring has been operating since at least March 2026.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
What the Threat Looks Like
Security researchers have uncovered nearly 77 Firefox extension identities tied to a threat actor now dubbed Offside Wallet Theft Factory. Of these, 40 are confirmed malicious add-ons; the other 37 posed as innocuous sports-score or browser tool extensions to evade detection and platform review.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) These extensions lure users with what appear to be harmless utilities, notepads, or wallet import interfaces. Under the surface, they’re harvesting highly sensitive material like 12- and 24-word recovery phrases during wallet setup or import.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
How the Attack Works
The malicious extensions rely heavily on Cloudflare Workers—serverless infrastructure provided by Cloudflare—to host endpoints that receive stolen secrets.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) After capturing a phrase or private key, the extension sends it to an attacker-controlled Cloudflare Worker.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) In some instances, altered wallet code copies serialized keyring data before the legitimate local encryption process even begins, enabling attackers to stash it remotely.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) Beyond that, certain add-ons display phishing-style import pages (imitating OKX, Portal, or generic Web3 wallets) to trick users into typing in their secrets manually.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
Some extensions embed remote-control capabilities using Supabase projects, enabling attackers to change behavior after installation or updates—switching from appearing innocent (such as a notepad) to launching a phishing interface.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) Others collect clipboard data and credentials via commands sent to hardcoded servers.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) These tactics help evade static reviews since the malicious behavior may be hidden until after the extension has been approved and distributed.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
Indicators of Compromise & What To Do
Researchers have published a complete list of SHA-256 hashes, extension IDs, names, and versions of many malicious add-ons.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/)) They’ve also identified Supabase URLs and Cloudflare Worker endpoints involved in data theft, and even HTTP servers receiving clipboard or credential data.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
Users are strongly urged to audit their installed Firefox extensions: remove anything suspicious, especially wallets or crypto-related tools from unfamiliar publishers. After updates, check for changes in behavior or additional permissions. Critically, never enter recovery phrases or private keys into browser popups, web pages, or untrusted add-on interfaces. If you’ve already input this data into a suspect extension, treat it as compromised—move assets to a new wallet and change passwords.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
Wider lessons also emerge for platform security: code reuse, rebranding, and deceptive descriptions are being leveraged to build stealthy chains of trust. That makes careful publisher verification and ongoing behavior monitoring essential.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
This isn’t the first time Firefox extensions have been abused to harvest credentials, tokens, or wallet secrets.([cybersecuritynews.com](https://cybersecuritynews.com/malicious-firefox-extensions-2/))
Why this matters: Crypto users often regard browser-based wallets or extensions as convenient—but these tools now represent a primary attack surface. Without smart vetting of extensions, even nominally safe browsers can become points of failure.