Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
A security firm has linked 77 Firefox extension identities to a campaign called the Offside Wallet Theft Factory, confirming 40 as malicious. These extensions impersonate popular crypto wallets, capturing recovery phrases through fake interfaces or modified code.
Intelligence analysis by Llama

A production line of counterfeit crypto wallet extensions has been targeting Firefox users, some of which spent months publishing live football scores before being converted into tools for stealing recovery phrases.
Imagine you're playing a game where you have to keep your secret code safe. But someone is making fake versions of the game that look real, and when you play, they steal your secret code. That's what's happening with these fake crypto wallet extensions. They look real, but they're actually stealing your secret code, which is your recovery phrase.
Analysis
Offside Wallet Theft Factory: A Campaign of Deception
The Offside Wallet Theft Factory is a campaign of deception that has been targeting Firefox users with a production line of counterfeit crypto wallet extensions. These extensions, which impersonate popular wallets such as OKX, Rabby Wallet, and TronLink, capture recovery phrases through fake interfaces or modified versions of real wallet code. The campaign has been linked to 77 extension identities, with 40 confirmed as malicious.
The threat research team at Socket, the security firm behind the discovery, published its findings last week. The team found that some of the extensions had spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases. This suggests that the attackers were using the extensions as a way to gather intelligence on their targets before launching their attacks.
The Offside Wallet Theft Factory is a reminder of the ongoing threat of malicious extensions in the crypto space. It highlights the importance of verifying the authenticity of wallet interfaces and being cautious when installing new extensions. Users should always check the extension's permissions and reviews before installing it, and be wary of any extensions that ask for sensitive information such as recovery phrases.
The Impact of the Offside Wallet Theft Factory
The Offside Wallet Theft Factory has had a significant impact on the crypto space, with many users falling victim to the attacks. The campaign has highlighted the need for greater security measures to be put in place to protect users from these types of attacks. This includes implementing better verification processes for extensions and providing users with more information about the permissions and reviews of extensions before they install them.
The Future of Crypto Wallet Security
The Offside Wallet Theft Factory is a wake-up call for the crypto space, highlighting the need for greater security measures to be put in place to protect users from these types of attacks. The future of crypto wallet security will depend on the ability of wallet providers to implement better verification processes for extensions and provide users with more information about the permissions and reviews of extensions before they install them. This will require a collaborative effort between wallet providers, extension developers, and users to create a more secure and trustworthy environment for crypto transactions.
Conclusion
The Offside Wallet Theft Factory is a reminder of the ongoing threat of malicious extensions in the crypto space. It highlights the importance of verifying the authenticity of wallet interfaces and being cautious when installing new extensions. The future of crypto wallet security will depend on the ability of wallet providers to implement better verification processes for extensions and provide users with more information about the permissions and reviews of extensions before they install them.
Key points
- 77 Firefox extension identities linked to a campaign called the Offside Wallet Theft Factory
- 40 extensions confirmed as malicious, impersonating popular crypto wallets
- Extensions capture recovery phrases through fake interfaces or modified code
- Attackers used extensions to gather intelligence on targets before launching attacks
If the crypto space can learn from this attack and implement better security measures, it could lead to a more secure and trustworthy environment for transactions. This could also lead to increased adoption and confidence in the space.
If the attackers are able to continue their campaign undetected, it could lead to a significant number of users falling victim to the attacks, resulting in financial losses and damage to the reputation of the crypto space.



