Loading prices…
🩸BEARISH

Firefox Add-Ons: Socket Finds 40 Draining Crypto Wallets

Nine of the 40 IDs first shipped as benign sports-score tools, the kind of identity swap that turns a trusted extension into a wallet drainer after the user already approved it.

Security firm Socket linked 40 Firefox add-on identities to a campaign it calls the "Offside Wallet Theft Factory," in which wallet-draining payloads targeted recovery phrases, private keys, and serialized keyrings. The campaign ran from at least March 9 through Aug. 3, with 77 identities tied to it overall; 40 contained confirmed malicious behavior, and 37 were deceptive sports-score shells whose analyzed versions carried no confirmed theft payload. Nine of the 40 had previously distributed benign-looking sports-score tools under the same Firefox IDs before swapping in wallet-stealing versions.

Why it matters

The supply-chain trick matters more than the count. Because Mozilla's signing model trusts an extension's identity once approved, swapping a benign build for a malicious one under the same ID passes the surface checks users rely on. Socket's version histories show activity clustering in April and late July, with several add-ons still live when reported to Mozilla. 0KX WEB3 was serving seven users mid-analysis before Mozilla pulled it. Anyone whose recovery phrase, private key, or wallet keyring reached one of the 40 versions has to treat the wallet as permanently compromised, since uninstalling the extension cannot revoke an exposed secret.

Market impact

The 40 broke into distinct attack paths: seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other wallet secrets, 13 were modified clones of Rabby wallet software that transmitted serialized keyrings before local encryption could protect them, and five harvested credentials and clipboard data. The exposure ladder is concrete. Users who typed a recovery phrase or private key into an affected build need to move remaining assets to a fresh wallet generated from a new recovery phrase. Those hit only by credential or clipboard variants need password resets, session terminations, and verification of any copied transfer destinations. Mozilla says it relies on automated risk indicators plus human review to catch these, and advises installing only extensions linked from the wallet provider's official site.

Frequently asked questions

  1. How did the malicious Firefox add-ons actually steal crypto wallets?

    They used four distinct attack paths: remote-controlled phishing loaders, recovery phrase and private key capture, modified Rabby clones that exfiltrated serialized keyrings before local encryption, and credential and clipboard harvesters.

  2. Why are nine of the malicious add-ons especially concerning?

    Those nine IDs first distributed benign sports-score tools, then swapped in wallet-draining payloads under the same trusted Firefox extension IDs, exploiting Mozilla's trust-by-identity model.

  3. Does uninstalling the add-on make a wallet safe again?

    No. Recovery phrases, private keys, and serialized keyrings exposed to any of the 40 versions remain compromised after the extension is removed, and must be rotated through a fresh wallet.

  4. What should someone who used an affected add-on do right now?

    Move remaining assets to a fresh wallet generated from a new recovery phrase if a recovery phrase, private key, or Rabby keyring was exposed; change passwords, terminate active sessions, and verify copied transfer addresses if only credentials or clipboard data were at risk.

  5. How did Mozilla respond to Socket's report?

    Mozilla removed several add-ons before Socket's publication, including 0KX WEB3, which was live with seven users during analysis. The organization says it relies on automated risk indicators plus human review to catch malicious wallet add-ons.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →