

Browser extensions have long been praised for adding convenience to our daily web browsing. Whether managing a Web3 portfolio, switching to dark mode, or keeping tabs on live sports scores, add-ons streamline our digital lives. However, cybersecurity researchers have recently uncovered a sophisticated, industrialised threat targeting cryptocurrency holders through the Mozilla Firefox extension store.
In an alarming discovery published by security firm Socket, a sweeping malicious operation dubbed the "Offside Wallet Theft Factory" has been identified. Linking dozens of extension identities through shared code and infrastructure, the campaign represents a refined tactic in Web3 credential harvesting—one that leverages user trust, strategic patience, and clever permission evasion.
Socket’s threat research team linked a total of 77 Firefox extension identities involved in the network, confirming at least 40 as overtly malicious. Mozilla signing records indicate that the operation ran actively from March to August, with several harmful add-ons remaining live and accessible until researchers alerted the platform.
The primary objective of these extensions is simple yet devastating: harvesting private seed phrases and account credentials from unsuspecting users. To achieve this, the malicious actors employed a variety of deceptive techniques designed to imitate trusted Web3 brands:
What makes the Offside Wallet Theft Factory particularly insidious is its patient, long-term approach to acquiring target victims. Rather than launching outright malware from day one, the campaign utilised a classic "bait and switch" strategy.
Researchers discovered that 37 extension identities were initially listed as innocuous utilities, primarily offering live sports scores for football, basketball, NBA, and American football matches. These initial versions shared legitimate API credentials for sports data providers and functioned exactly as advertised.
Once these add-ons established a clean track record, gathered positive reviews, and built a substantial base of installed users, the developers pushed stealth updates. Nine confirmed malicious extensions started as sports applications before updates wiped that functionality and quietly replaced it with wallet-stealing code. By inheriting the trust, review history, and install base of the original app, the malicious updates easily slipped past casual user scrutiny.
Crypto users are often advised to review extension permissions before installation, checking for broad access requests such as "read and change all your data on all websites". However, the operators behind this campaign demonstrated how easily permission checks can be circumscribed.
For example, a counterfeit OKX wallet extension uncovered during the investigation requested only two basic browser permissions: storage and tabs. Because the extension did not attempt to scrape arbitrary web pages or monitor external sites, its permission profile appeared entirely benign.
Instead of local code execution that might raise security flags, the add-on simply loaded a remote page that hosted the malicious recovery phrase interface. By serving content remotely, the attackers avoided triggering permission alarms while successfully harvesting credentials typed into the interface.
If you have interacted with any unverified Firefox wallet extension or entered your seed phrase into a suspicious interface, immediate remediation is required:
The discovery of the Offside Wallet Theft Factory highlights a broader, troubling trend across the Web3 ecosystem. Browser extensions represent a high-value attack vector because they bridge the gap between user interfaces and private cryptographic keys.
Similar threats continue to surface across other major platforms. For instance, Chrome extensions have been caught secretly injecting fee-siphoning code into decentralised exchange transactions, while desktop malware continues to hide inside pirated software, fake utility apps, and unofficial game downloads.
As attackers refine their ability to bypass automated store reviews, self-custody crypto users must remain exceptionally vigilant, relying on hardware wallets where possible and double-checking developer signatures before trusting any extension with their digital assets.
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
