40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools
Software supply-chain security firm Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto, including nine that had previously distributed sports-score tools under the same...
Archive context
Fresh in the current trading session. It maps to a high-priority topic hub.
Software supply-chain security firm Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto, including nine that had previously distributed sports-score tools under the same IDs.
Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions must treat that wallet as compromised because uninstalling the add-on cannot revoke an exposed secret.
The Aug. 19 report linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious behavior. The other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload.
The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July.
Infographic showing 77 Firefox wallet extension IDs, including 40 confirmed malicious extensions using phishing, credential theft, and wallet-draining techniques.Socket’s version histories show that the nine affected IDs were:
Firefox ID Earlier sports version Later malicious version [email protected] Quick Quick 7.4.0 Rabbit For Desktop 8.20.10 [email protected] Dial Open Pro 7.23.25 Web3 & EVM 9.50.10 [email protected] Quick Shield 5.7.1 Rby-WALLEТ 6.7.10 [email protected] Lite Swatch 6.5.21 abby-WALLEТ 7.10.10 [email protected] Key Pulse 8.1.21 RABB-Walleť 8.22.30 [email protected] Timer Pulse 5.5.5 Rabbit WALLЕТ 11.10.10 [email protected] Track Quick 6.10.24 RabbWALLЕТ 7.10.30/8.10.30 [email protected] Store Plus 8.3.18 RabbWALLЕТ 9.11.30 [email protected] Pomodoro Plus 9.13.24 RABB-WALLEТ 10.20.10Socket said several campaign add-ons were still live when it reported them to Mozilla. Its report noted that the remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication.
Related Reading Top-ranked Chrome ‘wallet’ sneakily steals crypto seedphrases What affected crypto users should doThe 40 malicious identities used distinct attack paths. Seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data.
A recovery phrase or private key can restore a wallet elsewhere, and a serialized keyring similarly exposes the wallet’s account state before encryption can protect it.
Anyone who entered one of those secrets, or used an affected build that transmitted its keyring, should move remaining assets to a fresh crypto wallet created from a new recovery phrase.
Users exposed only to the credential-and-clipboard group should change affected passwords, terminate active sessions where possible, and verify copied destination addresses. Wallet keys need rotation when wallet-secret or keyring exposure occurred.
Mozilla says it uses automated risk indicators and human review to identify malicious wallet add-ons, and advises users to install only extensions linked from the wallet provider’s official site.
Socket documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a campaign loss total.
The post 40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools appeared first on CryptoSlate.
Why this matters
This maps to the Security Incidents hub, so it can help confirm whether that theme is gaining breadth across the crypto news cycle.
Original source
Read on CryptoSlateRelated market context
Zilliqa points to hardware wallet flaw discarding entropy to expose crypto keys, enabling 683M ZIL theft
A recent Zilliqa Ledger bug exposed at least 6,772 accounts, according to the post-mortem, and enabled the theft of 683,130,969.66...
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
Forty are confirmed malicious, impersonating OKX, Rabby and TronLink to harvest recovery phrases from anyone who types one in.
AI scammers no longer need to hack your wallet if they can convince you to use it for them
Reported losses from deepfake scams in 2026 have already exceeded last year's total by 263%, according to TRM Labs, highlighting a...
Phantom’s plan to drop Sui exposes the hidden power wallet interfaces hold over user funds
Phantom will remove Sui from its wallet interface on Sept. 24, one month after announcing that it and Sui had decided to end the i...
Kraken Says ‘Dust Attack’ From Sanctioned HTX Wallet Locked Out Customers
Bitcoin Magazine Kraken Says ‘Dust Attack’ From Sanctioned HTX Wallet Locked Out Customers Crypto exchange Kraken clients were rep...
Monad proposes wallet upgrade to withstand lost keys, quantum attacks
Monad's proposal could set a new standard for blockchain security, enhancing resilience against future quantum threats and simplif...