40 Firefox add-ons were draining wallets — why uninstalling is not the fix
Software supply-chain security firm Socket says it found 40 Firefox add-on identities with confirmed malicious behavior,…
Software supply-chain security firm Socket says it found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto wallets, and that nine of them had previously distributed ordinary sports-score tools under the same identities. Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions should treat that wallet as compromised.
Those nine sports add-ons are the part worth understanding. An extension identity carries its history: the reviews, the installs, and the automatic updates already granted to it. When a version that steals wallet secrets ships under an identity people previously trusted, the theft arrives as a routine update rather than as a new download. Socket's Aug. 19 report links 77 identities to a group it provisionally calls the Offside Wallet Theft Factory; 40 showed confirmed malicious behavior, while the other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload. Mozilla signing records for the 59 versions Socket analyzed run from March 9 through Aug. 3, clustering in April and late July.
The 40 malicious identities did not all work the same way. Fifteen captured recovery phrases, private keys, or other wallet secrets. Thirteen were modified clones of Rabby wallet software that sent serialized keyrings out before local encryption could protect them. Seven were remote-controlled phishing loaders, and five collected credentials and clipboard data. Socket said several were still live when it reported them to Mozilla, including a remote-controlled phishing add-on called 0KX WEB3 that had seven users during analysis and was removed before publication.
This is the reason removal is not a remedy. A recovery phrase or a private key can restore a wallet anywhere, and a serialized keyring exposes the wallet's account state before encryption applies. Uninstalling the add-on takes away the tool, not the copy someone already has. If you entered a secret into one of these extensions, or used an affected build that transmitted its keyring, the recovery step is to create a new wallet from a new recovery phrase and move what remains to it.
If your exposure was only to the credential-and-clipboard group, the response is different and smaller: change the affected passwords, end active sessions where you can, and check destination addresses after pasting them, since clipboard access is how a pasted address gets quietly swapped. Key rotation is for wallet-secret or keyring exposure.
Mozilla says it uses automated risk indicators and human review to catch malicious wallet add-ons, and advises installing extensions only through the link on the wallet provider's own site. That habit is worth more than it sounds, because a browser extension sits exactly where you type things. Socket documented theft capability and exfiltration infrastructure but did not identify confirmed victims, attributable transactions, or a total loss figure, and the absence of a number is not evidence that nobody lost anything.