Nine add-ons shifted from sports-score tools to software targeting digital asset wallets
Socket identified 40 Firefox extensions with confirmed malicious behaviour targeting digital asset wallets. The August 19 report links 77 add-on identities to the “Offside Wallet Theft Factory”: 40 contained confirmed malicious behaviour, while 37 were deceptive sports-score shells or suspicious extensions with no confirmed theft payload in the versions analysed.
The campaign was active from at least March through August. Mozilla signing records for the 59 original versions analysed by Socket run from March 9 to August 3, with activity concentrated in April and late July. Nine identities had previously distributed sports-score tools under the same Firefox IDs before shifting to wallet-targeting software.
The 40 malicious identities used separate methods: seven remotely controlled phishing loaders, 15 add-ons that captured seed phrases, private keys or other wallet secrets, 13 modified clones of Rabby Wallet that sent serialised keyrings before local encryption, and five tools that collected credentials and clipboard data. Socket reported several still-active add-ons to Mozilla; 0KX WEB3 was active with seven users during the analysis and was removed before publication.
Anyone who entered a seed phrase or private key into an affected version, or used a clone that transmitted the keyring, should consider the wallet compromised and move remaining assets to a new wallet created with a new seed phrase. Users affected by the group collecting credentials and clipboard data should change the relevant passwords, end active sessions and verify copied addresses. Socket did not identify confirmed victims, attributable transactions or a total loss figure.





