header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Firefox now has 40 malicious cryptocurrency wallet extensions, disguising as the Rabby wallet, etc., to steal mnemonic phrases.

BlockBeats News, August 25th, Security company Socket has discovered a batch of malicious crypto wallet extensions targeting Firefox users, linking them to an attack campaign named "Offside Wallet Theft Factory." Currently, 77 extension identities have been linked, with 40 confirmed to exhibit malicious behavior, and the activity has been ongoing at least from March 2026 to August.


These extensions mainly masquerade as well-known Web3 wallets such as OKX, Rabby Wallet, TronLink, luring users to import their existing wallets through highly simulated wallet interfaces to steal mnemonic phrases or private keys. About half of them directly ask users to input mnemonic phrases, while 13 are tampered versions of Rabby that send wallet account information to external servers when users save it, and 5 extensions collect saved credentials and clipboard content.


Socket also found that at least 9 malicious extensions had previously operated in the form of sports score apps related to football, basketball, NBA, etc., accumulating users and ratings, and then replacing them with wallet-stealing code through updates. In addition, 37 extensions disguised as password generators, VPNs, currency converters, and other tools actually run sports score programs.


Socket reminds users that if they have entered their mnemonic phrases or private keys in any related extensions, they should consider their wallet credentials permanently compromised. Merely uninstalling the extensions cannot revoke the leaked mnemonic phrases or private keys that have already been exposed externally. Users should immediately transfer their assets to a brand-new wallet.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish