XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Massive Firefox Malware Campaign Impersonates Major Crypto Wallets to Steal Recovery Phrases

Security researchers uncovered 77 fraudulent Firefox extensions that impersonate popular Web3 wallets like OKX, Rabby, and TronLink, with at least 40 confirmed malicious and actively stealing cryptocurrency credentials.

JM
by Jacob Marquez · Learn Desk
Published August 25, 2026 · 3 min read

Largest Wallet Theft Campaign Targets Firefox Users

Security firm Socket has identified a sweeping malware campaign affecting Firefox users, branding it the “Offside Wallet Theft Factory.” The researchers linked 77 extension identities to the coordinated effort, confirming 40 as malicious. According to Mozilla signing records, the campaign operated from March 9 through August 3, 2026, with several extensions still active when Socket disclosed its findings. The scope and sophistication of the operation suggest a well-resourced threat actor capable of managing multiple vectors for stealing cryptocurrency secrets.

The malicious extensions specifically target popular crypto platforms, impersonating legitimate wallets including OKX, Rabby Wallet, and TronLink. The attackers used character substitutions designed to closely resemble authentic wallet names, making the fake extensions difficult to distinguish at a glance. The campaign reveals the vulnerability of browser-based wallet storage to sophisticated social engineering attacks, a critical concern for the broader cryptocurrency ecosystem.

Deceptive Tactics Hide Malware in Plain Sight

What distinguishes this campaign is the sophisticated layering of deception. Approximately half of the malicious extensions present fake wallet interfaces that prompt users to “import” an existing wallet, capturing whatever recovery phrase or private key the user enters. A further 13 extensions are modified versions of the legitimate Rabby wallet that operate normally while secretly exfiltrating stored account data to external servers. Five additional variants collect saved passwords and clipboard contents—a particularly effective technique since users often copy-paste sensitive information.

Beyond the obvious wallet impersonators, 37 extensions disguised themselves as unrelated tools: password generators, dark mode toggles, VPN services, currency converters, and note-taking applications. These posed as legitimate utilities with genuine functionality, making detection even harder. Notably, nine of these initially published real sports-score applications before later updates silently replaced that code with wallet-stealing functionality, inheriting their existing user base and review history in the process. This phased approach—first establishing trust, then converting to malware—demonstrates calculated precision in social engineering.

Security Implications for the Crypto Community

Socket cautioned that it has not identified a single operator behind the entire campaign, suggesting the infrastructure may be shared or sold among multiple threat actors. One particularly revealing finding: a counterfeit OKX wallet requested only two permissions (storage and tabs), demonstrating that traditional permission-based defenses provide limited protection against determined attackers. The malware never needed to search the browser’s data—it simply loaded a remote page and waited for users to voluntarily enter their secrets.

This campaign underscores the ongoing tension between cryptocurrency’s promise of self-custody and the real risks users face when adopting browser-based wallet solutions. As the ecosystem matures, so do the attacks against it, making security awareness and verification of official sources critical for all crypto users holding assets on networks from Bitcoin to XRP.

Browser-based wallet compromises like these represent a direct threat to user funds across all blockchains, including the XRP Ledger, emphasizing why users must verify wallet authenticity and consider hardware-based security solutions.

Source: Socket, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.