- Security firm Socket says it is tracking 77 Firefox add-on identities linked to crypto theft. Only 40 have confirmed malicious behaviour.
- Nine of those 40 sat on listing IDs that had previously carried working sports-score add-ons, so any ratings or history belonged to the earlier build.
- Socket documents the code, not the damage. It publishes no victim count, no stolen total and no evidence.
Checking a browser add-on’s reviews before you install it is sensible advice, and it is the advice that fails here. Socket, a firm that scans software packages for malicious code, says nine Firefox extensions it confirmed as wallet stealers were living on listing IDs that had earlier held ordinary football, basketball and NBA score tools.
An add-on that has been sitting in your browser for months, doing what it said it would do, can be replaced through a routine update with something built to read your . Reviews, install counts and a track record were earned by the old version and carry over to the new one. And if a phrase was ever typed into one of these windows, removing the add-on does not undo it. The wallet has to be treated as gone, whatever the balance looks like today.
What an extension can actually see

A browser extension is a small program that runs inside Firefox or Chrome with permission to watch and change the pages you visit. That is the whole point of them: an ad blocker has to see the page to strip the ads out of it. The same access means an extension can read what you type into a form, including a form it drew itself.
That is the mechanism behind almost every fake wallet add-on. It puts up a convincing OKX or Rabby interface, asks you to “restore” or “verify” your wallet, and sends the twelve or twenty-four words straight out to a server. No wallet, exchange, support agent or browser tool ever needs your recovery phrase or . A request for one is a theft attempt every single time, regardless of how well the logo has been copied.
Socket’s technical breakdown splits the 40 confirmed extensions four ways: seven used remote switches to turn phishing pages on and off, fifteen captured recovery phrases and private keys and sent them out through Cloudflare Workers, thirteen were modified builds of the real Rabby wallet that copied the stored keyring before it was encrypted, and five went after saved credentials and clipboard contents. The impersonated brands included OKX, Rabby and TronLink, often under homoglyph names like “0KX WEB3” and “RABB-Walӏet” that read correctly at a glance.
The reused-ID trick
Every Firefox add-on has an ID that stays fixed for the life of the listing. Updates arrive under that ID, usually automatically, and the page keeps its history. Socket’s version records show nine of the confirmed-malicious IDs previously shipped sports-score add-ons: bright-save-feed@tabtools.org ran as “Quick Quick”, a football tool; deep-tip-sharp@browsify.co as “Quick Shield”, basketball; fast-zip-true@smartext.co as “Pomodoro Plus”, NBA scores. All of them called the same paid sports data service using one shared, hardcoded key.
What Socket does not show is how many people had those earlier versions installed, or that anyone actually received the malicious update through auto-update. It shows one earlier sports build per ID with matching file hashes. That is a documented pattern in the signing record. It is not a measured number of victims.
What the 77 figure covers
Socket’s own headline is “77 Firefox Extensions Linked to Crypto Wallet and Credential Theft”, and the gap between that number and 40 matters. The remaining 37 are what Socket calls a coordinated multi-sport score-shell operation: listings advertising password generators, dark mode, VPNs and note taking that all quietly call the same sports API. Of those, Socket writes: “Their analyzed builds contain no confirmed credential- or wallet-stealing payloads.” Suspicious and deceptive, in the firm’s classification. Not shown to steal anything.
The link between the 77 comes from shared code, cloned listings, matching ID patterns and clustered signing dates rather than from any identified operator. Socket is careful about this: “Attribution remains under investigation, and the available evidence does not establish that a single threat actor controls every extension.” It says it is “provisionally tracking this campaign as “Offside Wallet Theft Factory””, a name of its own coining.
Scale is the other thing missing. The single listing where Socket gives a user count, the fake 0KX WEB3, showed seven users when reviewed. There is no aggregate install figure in the report, no stolen-funds total and no on-chain transactions. The evidence is static analysis of signed packages: exfiltration endpoints, a campaign , hooks into wallet storage. Capability, demonstrated. Losses, unmeasured.
Mozilla removed the 0KX WEB3 listing before the report went out, and Socket credits its Add-ons Operations team. But Socket also says several extensions were still live when it reported them, and there is no confirmation from Mozilla that all 77 are now gone. Signing dates for the original 59 versions analysed run from 9 March to 3 August, clustering in April and late July. The 18 identities added later have no published dates at all.
If you have one of these installed
Open Firefox’s add-ons page and read the whole list, not just the ones you recognise. Anything wallet-related that you do not remember installing deliberately should go, and anything that has ever shown you a seed-phrase or private-key field should be treated as a compromise: move the funds to a wallet created from a fresh phrase on a device that never had the add-on, because the exposed one cannot be repaired. Our self-custody guide covers setting one up properly.
In the UK, losses of this kind go to Action Fraud, online or on 0300 123 2040, and to your bank straight away if card or account details were also stored in the browser.
What to watch
Whether Mozilla publishes blocklist entries for the full set, which would confirm the removals that Socket cannot. Whether a second analyst reproduces the findings against Socket’s published file hashes. And whether the sports-shell 37, currently classed as deceptive but not proven to steal, ever ship a payload. A dormant listing with real reviews on it is the asset here, and this campaign has 37 more of them.