Massive Firefox Malware Campaign Impersonates Major Crypto Wallets to Steal Recovery Phrases
Security researchers uncovered 77 fraudulent Firefox extensions that impersonate popular Web3 wallets like OKX, Rabby, and TronLink, with at least 40 confirmed malicious and actively stealing cryptocurrency credentials.
Largest Wallet Theft Campaign Targets Firefox Users
Security firm Socket has identified a sweeping malware campaign affecting Firefox users, branding it the “Offside Wallet Theft Factory.” The researchers linked 77 extension identities to the coordinated effort, confirming 40 as malicious. According to Mozilla signing records, the campaign operated from March 9 through August 3, 2026, with several extensions still active when Socket disclosed its findings. The scope and sophistication of the operation suggest a well-resourced threat actor capable of managing multiple vectors for stealing cryptocurrency secrets.
The malicious extensions specifically target popular crypto platforms, impersonating legitimate wallets including OKX, Rabby Wallet, and TronLink. The attackers used character substitutions designed to closely resemble authentic wallet names, making the fake extensions difficult to distinguish at a glance. The campaign reveals the vulnerability of browser-based wallet storage to sophisticated social engineering attacks, a critical concern for the broader cryptocurrency ecosystem.
Deceptive Tactics Hide Malware in Plain Sight
What distinguishes this campaign is the sophisticated layering of deception. Approximately half of the malicious extensions present fake wallet interfaces that prompt users to “import” an existing wallet, capturing whatever recovery phrase or private key the user enters. A further 13 extensions are modified versions of the legitimate Rabby wallet that operate normally while secretly exfiltrating stored account data to external servers. Five additional variants collect saved passwords and clipboard contents—a particularly effective technique since users often copy-paste sensitive information.
Beyond the obvious wallet impersonators, 37 extensions disguised themselves as unrelated tools: password generators, dark mode toggles, VPN services, currency converters, and note-taking applications. These posed as legitimate utilities with genuine functionality, making detection even harder. Notably, nine of these initially published real sports-score applications before later updates silently replaced that code with wallet-stealing functionality, inheriting their existing user base and review history in the process. This phased approach—first establishing trust, then converting to malware—demonstrates calculated precision in social engineering.
Security Implications for the Crypto Community
Socket cautioned that it has not identified a single operator behind the entire campaign, suggesting the infrastructure may be shared or sold among multiple threat actors. One particularly revealing finding: a counterfeit OKX wallet requested only two permissions (storage and tabs), demonstrating that traditional permission-based defenses provide limited protection against determined attackers. The malware never needed to search the browser’s data—it simply loaded a remote page and waited for users to voluntarily enter their secrets.
This campaign underscores the ongoing tension between cryptocurrency’s promise of self-custody and the real risks users face when adopting browser-based wallet solutions. As the ecosystem matures, so do the attacks against it, making security awareness and verification of official sources critical for all crypto users holding assets on networks from Bitcoin to XRP.
Browser-based wallet compromises like these represent a direct threat to user funds across all blockchains, including the XRP Ledger, emphasizing why users must verify wallet authenticity and consider hardware-based security solutions.
Source: Socket, via Decrypt. Not financial advice.