Fake Firefox Web3 Extensions Steal Wallet Secrets

The Hacker News · High sophistication
Last updated August 20, 2026

Researchers found 40 malicious Firefox extensions pretending to be popular Web3 wallet products (like OKX, Rabby Wallet, and TronLink) to steal crypto wallet secrets. The extensions trick users into installing them, then capture recovery phrases/private keys and send them to attacker-controlled online infrastructure.

Key findings

  • 40 Firefox extensions were confirmed malicious and masqueraded as OKX, Rabby Wallet, TronLink, and other Web3 products.
  • Campaign name: 'Offside Wallet Theft Factory'; believed active since March 2026; not attributed to a known threat actor.
  • 15 extensions captured recovery phrases/private keys and exfiltrated them via Cloudflare Workers.
  • 13 modified Rabby Wallet builds exfiltrated serialized keyrings before local encryption.
  • Some extensions were initially benign-looking 'sports score' or utility add-ons, then later repurposed into wallet-stealing malware under the same Firefox ID.
  • Attackers used shared source code/infrastructure across a broader set of 77 add-ons; some used Supabase projects as remote switches to serve phishing/decoy content.

Who’s being targeted

  • Commonly targeted roles: All employees (browser extension hygiene), Finance, Executives, IT/Endpoint Management, Employees using cryptocurrency/Web3 wallets.
  • Affected industries: Cryptocurrency/Web3, Finance, Technology/Software.
  • Attack channels: website.
  • Impersonated: OKX / Rabby Wallet / TronLink (counterfeit extension), Sports scores/utility extension (later repurposed).

Awareness takeaways

  • Treat any browser extension that asks for a wallet recovery phrase/private key as a likely scam; never enter seed phrases into unverified add-ons.
  • Don’t assume an add-on is safe just because it’s in an official marketplace, verify the publisher and extension history before installing.
  • Watch for extensions that change purpose after updates (e.g., sports/utility → wallet tool). Re-review permissions and remove anything suspicious.
  • Assume attackers will quickly rebrand and re-publish look-alike extensions; rely on allowlists and managed browser controls rather than name recognition.

Red flags to watch for

  • Extension branding/name mimics a real wallet but is slightly altered (look-alike names/characters).
  • Extension asks for recovery phrase/private key (high-risk request).
  • Add-on appears to change behavior over time after updates (benign utility → wallet tool).
  • Extension’s stated purpose changes over time (sports/utility → wallet/security tool).
  • Unexpected prompts for credentials, wallet secrets, or clipboard access.
  • Publisher identity/name/ID changes frequently (rotating names and IDs).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You open Firefox and see this: “Install Rabby Wallet for Firefox to manage your Web3 assets.” Looks legit, right? Researchers just found 40 Firefox extensions in a campaign called Offside Wallet Theft Factory, copying OKX, Rabby Wallet, and TronLink to steal crypto. They ask you to import your recovery phrase, then silently ship it out through Cloudflare Workers and other cloud services. Here’s the nasty twist: some started as harmless sports-score or utility add-ons. After a few updates, that “NBA scores” extension quietly turns into a wallet tool, suddenly asking for seed phrases or clipboard access while still under the same Firefox ID. Your move: if any browser extension, Firefox, Chrome, anything, ever asks for your wallet recovery phrase or private key, stop and close it. That request alone is your cue to uninstall and report it.

Similar attacks

Fake Firefox Wallet Add-ons Steal Seed Phrases

Fake Firefox Wallet Add-ons Steal Seed Phrases

Researchers found a campaign of malicious Firefox add-ons that look like legitimate crypto wallets, VPNs, or utilities but are designed to trick people into entering wallet recovery phrases or exposing credentials. The add-ons can switch from harmless decoys (like a notepad or sports scores) to a…

August 24, 2026
Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI…

September 2, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Recruiters Lure Devs Into Malware “Coding Tests”

Fake Recruiters Lure Devs Into Malware “Coding Tests”

An Iran-linked espionage group contacted developers and other tech specialists with fake job offers on LinkedIn and similar platforms. Victims were pushed to quickly download and run “coding challenges” that secretly installed new malware, giving attackers remote access and long-term persistence.…

September 1, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Web3 Job Interviews Push “ClickFix” Malware

Fake Web3 Job Interviews Push “ClickFix” Malware

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During the test, victims are tricked into copying a terminal command to “fix” a camera/mic error, which installs remote-access malware and can lead…

July 21, 2026