A security firm has uncovered a campaign involving dozens of counterfeit Firefox extensions designed to steal cryptocurrency recovery phrases and credentials. According to research published by Socket, the campaign—dubbed the Offside Wallet Theft Factory—features 77 linked extension identities, with 40 confirmed as malicious.
Mozilla signing records indicate the activity spanned from March 9 to August 3, with several extensions remaining live at the time of the report. The malicious add-ons frequently impersonate well-known Web3 products such as OKX, Rabby Wallet, and TronLink by utilizing names closely resembling the legitimate services.
The threat research team detailed multiple methods used by the extensions to compromise users:
- Approximately half of the malicious tools present a convincing wallet interface prompting users to import an existing wallet, subsequently harvesting entered recovery phrases or private keys.
- Thirteen extensions utilize modified builds of Rabby Wallet that operate normally while simultaneously transmitting stored account data to an external server.
- Five extensions gather saved credentials and clipboard contents.
- Another 37 identities pose as unrelated utilities such as password generators, dark mode toggles, currency converters, note-taking tools, and VPNs, but actually function as live sports-score applications.
Notably, nine of the confirmed malicious extensions initially launched as sports-score apps for football, basketball, NBA, or American football before later updates replaced the code with wallet-stealing functions. This tactic allowed the operators to leverage the existing install base and review history built by the benign applications.
Socket noted that one counterfeit OKX wallet requested only minimal permissions—specifically storage and tabs—because it simply loaded a remote page and waited for users to input a recovery phrase. The firm warned that browser permissions alone may not be sufficient to evaluate an extension's safety.
Users who entered their recovery phrase or private key into any of the compromised extensions are advised to treat their credentials as permanently compromised and immediately transfer funds to a new wallet, as simply uninstalling the extension does not revoke data already transmitted to third parties.


