Fake Firefox Wallet Add-ons Steal Seed Phrases

Graham Cluley · Medium sophistication
Last updated August 25, 2026

Researchers found a campaign of malicious Firefox add-ons that look like legitimate crypto wallets, VPNs, or utilities but are designed to trick people into entering wallet recovery phrases or exposing credentials. The add-ons can switch from harmless decoys (like a notepad or sports scores) to a convincing “import your wallet” screen controlled remotely via a cloud database, enabling theft without pushing a visible update.

How the attack worked

Researchers identified a wide campaign of malicious Firefox add-ons designed to look like legitimate crypto wallets, VPNs, or simple utilities. One sample, called "0KX WEB3," used a lookalike name mimicking the OKX cryptocurrency exchange by swapping a zero in for the letter O, and contained no actual wallet code. Instead, the extensions were built to display a fake wallet-import screen that prompts users to enter their recovery phrase. Anyone who does so hands that phrase straight to the attackers, who can then drain the associated wallet.

What made this campaign notable was the remote control mechanism. The extensions could switch between a harmless decoy, like a notepad or a sports scoreboard, and the credential-stealing screen on command, using a cloud-hosted database to flip that switch without requiring a visible update. Out of 77 linked extensions identified, 40 were confirmed to actively steal information.

Why it succeeded

The campaign worked because it exploited trust assumptions people commonly make about browser extensions. Several of the extensions confirmed to steal cryptocurrency began life as innocuous sports-score shells, only to be updated after installation to swap that scoreboard for a wallet-draining interface. Because extensions can be updated post-install, an add-on that looked safe at the time of installation was not guaranteed to remain that way. The extensions also asked for very few permissions, reinforcing a false sense of safety for users who judge trustworthiness mainly by permission requests.

What to watch for

  • Any browser-based prompt asking you to enter a wallet recovery or seed phrase
  • Lookalike branding or names, such as a zero substituted for a letter in a well-known brand
  • An extension's behavior or interface changing unexpectedly after installation
  • Extensions tied to unusual shared infrastructure with other suspicious add-ons

How to build resistance

A legitimate wallet is not going to ask you to enter your recovery phrase on a webpage, so any such request should be treated as an immediate stop signal. Only install extensions from well-known, verified publishers, and apply extra scrutiny to anything that offers to manage cryptocurrency from inside the browser. Do not judge an extension's trustworthiness purely by the permissions it requests, since some of the most dangerous extensions in this campaign asked for almost nothing. Finally, review installed extensions regularly and remove anything unrecognized or no longer needed, since an add-on that was safe at install time can later be updated to include malicious code.

Key findings

  • Socket identified “scores of malicious linked Firefox add-ons” designed to steal wallet seed phrases or passwords.
  • The campaign is dubbed “Offside Wallet Theft Factory” and has been active “since at least March 2026.”
  • A sample extension “0KX WEB3” mimics OKX (using a zero instead of the letter O) and contains “no wallet code.”
  • The extensions can remotely toggle between benign decoy screens and a wallet-import phishing screen via a Supabase-hosted database.
  • “Out of the 77 linked extensions, 40 were confirmed… to steal information.”
  • Extensions can be updated after install; some began as sports-score shells before being turned into crypto-stealers.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, Employees who use cryptocurrency, IT / Security awareness trainees.
  • Affected industries: Cryptocurrency users / personal finance, Financial services / crypto exchanges, Technology (browser extension ecosystems).
  • Attack channels: website.
  • Impersonated: OKX crypto wallet (lookalike extension “0KX WEB3”), Browser utility extension (sports scores, VPN, password generator, note-taking tool).

Red flags to watch for

  • A “wallet” asking for a recovery phrase on a webpage-like screen
  • Lookalike branding/name (e.g., “0KX” using a zero)
  • Extension behavior can change unexpectedly after installation (decoy swaps to wallet prompt)
  • An extension that changes purpose or UI after installation
  • An extension tied to unusual shared infrastructure with other shady add-ons
  • Over-trust based on “few permissions” alone
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do these malicious Firefox extensions steal crypto wallet seed phrases?

They display a convincing wallet-import screen that asks users to type in their recovery phrase, which is then sent directly to the attackers controlling the extension.

Why did these extensions pass as safe on the Firefox add-on store?

Many started as harmless decoys, such as sports score trackers or note-taking tools, and only later were updated after installation to add malicious wallet-theft behavior.

Does requesting few permissions mean a browser extension is safe?

No. Some of the most dangerous extensions in this campaign asked for almost no permissions, showing that permission scope alone is not a reliable trust signal.

What should someone do if an extension asks for a wallet recovery phrase?

Treat it as a major red flag and stop immediately, since a legitimate wallet does not ask users to enter a recovery phrase on a webpage.

Read the video transcript

You install a Firefox sports-score add-on… and a week later it suddenly says, “Import your wallet to continue.” Researchers call this the Offside Wallet Theft Factory: fake Firefox add-ons like “0KX WEB3” that mimic real wallets, then flip from harmless decoys to a seed-phrase phishing screen controlled from a cloud database. Here’s the trick: by flipping a switch in that database, the add-on swaps its UI and tells you to enter your recovery phrase. Victims who type it there hand their entire wallet straight to the attackers. If any extension ever asks for a wallet recovery or seed phrase, stop right there, close it, and remove that add-on from Firefox immediately.

Similar attacks

Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Firefox Web3 Extensions Steal Wallet Secrets

Fake Firefox Web3 Extensions Steal Wallet Secrets

Researchers found 40 malicious Firefox extensions pretending to be popular Web3 wallet products (like OKX, Rabby Wallet, and TronLink) to steal crypto wallet secrets. The extensions trick users into installing them, then capture recovery phrases/private keys and send them to attacker-controlled…

August 20, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
OkoBot Fakes Wallet App Screens to Steal Seed Phrases

OkoBot Fakes Wallet App Screens to Steal Seed Phrases

A real malware campaign called OkoBot is infecting Windows PCs and then showing a fake “recovery phrase” prompt inside legitimate Ledger and Trezor desktop apps. Victims are tricked into typing their wallet seed phrase into a malicious page that looks like it came from the trusted app, allowing…

July 15, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026