BlockBeats News, August 25th, Security company Socket has discovered a batch of malicious crypto wallet extensions targeting Firefox users, linking them to an attack campaign named "Offside Wallet Theft Factory." Currently, 77 extension identities have been linked, with 40 confirmed to exhibit malicious behavior, and the activity has been ongoing at least from March 2026 to August.
These extensions mainly masquerade as well-known Web3 wallets such as OKX, Rabby Wallet, TronLink, luring users to import their existing wallets through highly simulated wallet interfaces to steal mnemonic phrases or private keys. About half of them directly ask users to input mnemonic phrases, while 13 are tampered versions of Rabby that send wallet account information to external servers when users save it, and 5 extensions collect saved credentials and clipboard content.
Socket also found that at least 9 malicious extensions had previously operated in the form of sports score apps related to football, basketball, NBA, etc., accumulating users and ratings, and then replacing them with wallet-stealing code through updates. In addition, 37 extensions disguised as password generators, VPNs, currency converters, and other tools actually run sports score programs.
Socket reminds users that if they have entered their mnemonic phrases or private keys in any related extensions, they should consider their wallet credentials permanently compromised. Merely uninstalling the extensions cannot revoke the leaked mnemonic phrases or private keys that have already been exposed externally. Users should immediately transfer their assets to a brand-new wallet.

