discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

A security firm has linked 77 Firefox extension identities to a campaign called the Offside Wallet Theft Factory, confirming 40 as malicious. These extensions impersonate popular crypto wallets, capturing recovery phrases through fake interfaces or modified code.

By Decrypt·Aug 25·decrypt.co·3 min read

Intelligence analysis by Llama

firefox malware crypto malware
firefox malware crypto malwareImage: decrypt.co

A production line of counterfeit crypto wallet extensions has been targeting Firefox users, some of which spent months publishing live football scores before being converted into tools for stealing recovery phrases.

Why it matters

This story matters to anyone following the crypto space, as it highlights the ongoing threat of malicious extensions and the importance of verifying the authenticity of wallet interfaces.

Imagine you're playing a game where you have to keep your secret code safe. But someone is making fake versions of the game that look real, and when you play, they steal your secret code. That's what's happening with these fake crypto wallet extensions. They look real, but they're actually stealing your secret code, which is your recovery phrase.

Analysis

Offside Wallet Theft Factory: A Campaign of Deception

The Offside Wallet Theft Factory is a campaign of deception that has been targeting Firefox users with a production line of counterfeit crypto wallet extensions. These extensions, which impersonate popular wallets such as OKX, Rabby Wallet, and TronLink, capture recovery phrases through fake interfaces or modified versions of real wallet code. The campaign has been linked to 77 extension identities, with 40 confirmed as malicious.

The threat research team at Socket, the security firm behind the discovery, published its findings last week. The team found that some of the extensions had spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases. This suggests that the attackers were using the extensions as a way to gather intelligence on their targets before launching their attacks.

The Offside Wallet Theft Factory is a reminder of the ongoing threat of malicious extensions in the crypto space. It highlights the importance of verifying the authenticity of wallet interfaces and being cautious when installing new extensions. Users should always check the extension's permissions and reviews before installing it, and be wary of any extensions that ask for sensitive information such as recovery phrases.

The Impact of the Offside Wallet Theft Factory

The Offside Wallet Theft Factory has had a significant impact on the crypto space, with many users falling victim to the attacks. The campaign has highlighted the need for greater security measures to be put in place to protect users from these types of attacks. This includes implementing better verification processes for extensions and providing users with more information about the permissions and reviews of extensions before they install them.

The Future of Crypto Wallet Security

The Offside Wallet Theft Factory is a wake-up call for the crypto space, highlighting the need for greater security measures to be put in place to protect users from these types of attacks. The future of crypto wallet security will depend on the ability of wallet providers to implement better verification processes for extensions and provide users with more information about the permissions and reviews of extensions before they install them. This will require a collaborative effort between wallet providers, extension developers, and users to create a more secure and trustworthy environment for crypto transactions.

Conclusion

The Offside Wallet Theft Factory is a reminder of the ongoing threat of malicious extensions in the crypto space. It highlights the importance of verifying the authenticity of wallet interfaces and being cautious when installing new extensions. The future of crypto wallet security will depend on the ability of wallet providers to implement better verification processes for extensions and provide users with more information about the permissions and reviews of extensions before they install them.

Key points

  • 77 Firefox extension identities linked to a campaign called the Offside Wallet Theft Factory
  • 40 extensions confirmed as malicious, impersonating popular crypto wallets
  • Extensions capture recovery phrases through fake interfaces or modified code
  • Attackers used extensions to gather intelligence on targets before launching attacks
The Upside

If the crypto space can learn from this attack and implement better security measures, it could lead to a more secure and trustworthy environment for transactions. This could also lead to increased adoption and confidence in the space.

The Downside

If the attackers are able to continue their campaign undetected, it could lead to a significant number of users falling victim to the attacks, resulting in financial losses and damage to the reputation of the crypto space.

Originally reported at

decrypt.co

Discernion covers the story. Read the full piece at the source.

Tagscryptosecuritymalwarefirefoxextensions

Author

Decrypt

Intelligence analysis by

Llama

Published

Aug 25, 2026

Source

decrypt.co

Share

Topics

cryptosecuritymalwarefirefoxextensions

Related

More from this desk

fraud crypto fraud trading bot
Aug 25·decrypt.co

Crypto Fund Founder Convicted of Fraud Over Fake Trading Bot

A federal jury has convicted Japheth Dillman of wire fraud and conspiracy over the collapse of crypto fund Block Bits Capital. He told investors the fund's automated trading software was complete and working when he knew it was not.

Aug 25·cointelegraph.com

Arcus Launches Tokenized Perp Positions on Robinhood Chain

Arcus, a decentralized exchange (DEX), has launched a protocol on Robinhood Chain that converts perpetual futures positions into transferable ERC-20 tokens and allows tokenized stocks to be used as collateral for leveraged trading.

Grayscale ETFs Zcash ZEC Grayscale Zcash Trust ZCSH
Aug 25·decrypt.co

Grayscale Launches Zcash ETF Following Critical Privacy Flaw That Rocked the Cryptocurrency

Grayscale's Zcash fund began trading on NYSE Arca under the ticker ZCSH, following the disclosure and patching of a critical vulnerability in Zcash's shielded transaction system.

coinbase Tokenized stocks Base alpaca
Aug 25·decrypt.co

Coinbase Puts Tokenized Stocks on Base

Coinbase has launched tokenized stocks on its Base platform, allowing users to hold fractional shares of Apple and Nvidia in a self-custody wallet. The move aims to provide greater accessibility to equity ownership.