Crypto
Home›Crypto›Regulation›Malicious Firefox add-ons drained crypto wallet secret…
Malicious Firefox add-ons drained crypto wallet secrets, Socket warns
Socket says 40 Firefox add-on identities were confirmed malicious, including versions used to distribute sports-score tools and steal recovery phrases or private keys.
Software supply-chain security firm Socket identified 40 Firefox add-on identities with confirmed malicious behavior, including add-ons designed to drain crypto wallets.
Socket said anyone whose recovery phrase, private key, or wallet keyring reached a malicious version should treat the wallet as compromised, because uninstalling the add-on cannot revoke secrets that were already exposed.
The Aug. 19 report tied 77 identities to what Socket provisionally called the “Offside Wallet Theft Factory,” with 40 showing confirmed theft-related behavior and the rest described as deceptive or suspicious sports-score shells that lacked a confirmed theft payload.
Socket said the campaign operated from at least March into August, and noted some malicious add-ons were still live when it reported them to Mozilla, including a remote-controlled phishing add-on labeled 0KX WEB3 that Mozilla removed before publication. Socket did not identify confirmed victims, attributable transactions, or a total loss figure.