
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access to your savings.
Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.
The campaign, which researchers have dubbed the "Offside Wallet Theft Factory", has been running under the radar since at least March 2026.
One example of a malicious extension is called "0KX WEB3" (which uses a zero rather than the letter "O" in an attempt to mimic the OKX cryptocurrency exchange).

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.
Behind the scenes, the extension silently checks a database on Supabase, a legitimate cloud service, every time it is opened. Hackers controlling the database can decide what happens next.
By flipping a switch in the database, the attackers can toggle the extension's behaviour - most of the time it shows a harmless decoy, like a notepad, but on command it swaps to a convincing-looking page inviting users to import their wallet.

Victims who enter their recovery phrase there hand it straight to the attackers. Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.
What is so crafty about this is that the extension itself does so little. It only requires a minimal number of permissions to install. That's a useful reminder to everyone that just because an extension asks for very few permissions does not mean it is automatically safe.
Out of the 77 linked extensions, 40 were confirmed by security experts to steal information.
The remaining 37 presented themselves as VPNs, password generators, or note-taking tools — but secretly ran code that tracked NBA, hockey, or football scores. Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.
In fact, several of the extensions that have been confirmed to steal cryptocurrency wallet started as one of the same sports score shells - and only later got "updated" to swap their scoreboard for something that could end up draining a victim's finances.
Cybercriminals have used browser add-ons as a route into crypto wallets many times before.
For instance, in 2020 I wrote about 49 Chrome browser extensions that could steal passphrases and private keys, propped up with fake five-star reviews. More recently I described how over 100 malicious Chrome extensions had been caught stealing Google and Telegram data from 20,000 users, and this April how fake ChatGPT extensions were stealing login credentials.
Cybercriminals have learnt that if you dress malware up as something that people want, they can sit back and wait for the riches to roll in.
So, what can you do to better protect yourself?
tags
Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s.
View all posts