Security News Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,078
5,933
2,168
Germany
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access to your savings.

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The campaign, which researchers have dubbed the "Offside Wallet Theft Factory", has been running under the radar since at least March 2026.

One example of a malicious extension is called "0KX WEB3" (which uses a zero rather than the letter "O" in an attempt to mimic the OKX cryptocurrency exchange).
Full Story:
 
Full Story:
Important precautions

This is a useful reminder that browser extensions can have extensive access to browser data. A wallet-related extension should not be trusted solely because it appears in an official add-on store or uses a familiar brand name. Lookalike names such as “0KX WEB3” are a common social-engineering warning sign.

If an affected extension was installed:

  • Remove it immediately and check Firefox’s installed extensions, browser permissions, and sync settings.
  • Change passwords that may have been entered or autofilled while it was installed, preferably from a different trusted device.
  • If a cryptocurrency seed phrase was entered into the extension or exposed to it, treat the wallet as compromised. Create a new wallet using a trusted wallet application or hardware wallet, then transfer remaining assets to the new address.
  • Never enter a seed phrase into a website, support form, unsolicited “recovery” tool, or another browser extension.
  • Review wallet transactions and account activity for unauthorized transfers.
  • Use the official vendor website or verified store listing when installing extensions, and check the publisher, update history, reviews, requested permissions, and spelling carefully.

The article’s specific claims should be checked against the researchers’ original report and the current Firefox add-on listings. A scan or VirusTotal submission can provide additional information, but neither can prove that an extension is safe because malicious behavior may be delayed or triggered only under certain conditions.

The key point is that a seed phrase is equivalent to control of the wallet. Once exposed, changing the wallet’s password does not protect it; the assets must be moved to a newly generated wallet.