Close Menu
    Facebook X (Twitter) Instagram
    Facebook Instagram YouTube
    Crypto Go Lore News
    Subscribe
    Wednesday, August 26
    • Home
    • Market Analysis
    • Latest
      • Bitcoin News
      • Ethereum News
      • Altcoin News
      • Blockchain News
      • NFT News
      • Market Analysis
      • Mining News
      • Technology
      • Videos
    • Trending Cryptos
    • AI News
    • Market Cap List
    • Mining
    • Trading
    • Contact
    Crypto Go Lore News
    Home»Trending Cryptos»40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools
    Trending Cryptos

    40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools

    CryptoExpertBy CryptoExpertAugust 26, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools
    Share
    Facebook Twitter Pinterest Email Copy Link
    Ledger


    Software supply-chain security firm Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto, including nine that had previously distributed sports-score tools under the same IDs.

    Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions must treat that wallet as compromised because uninstalling the add-on cannot revoke an exposed secret.

    The Aug. 19 report linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious behavior. The other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload.

    The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July.

    Tokenmetrics
    Infographic showing 77 linked Firefox add-on IDs split into 40 malicious and 37 deceptive sports shells, with nine IDs repurposed and separate remediation for crypto wallet-secret and credential exposure.
    Infographic showing 77 Firefox wallet extension IDs, including 40 confirmed malicious extensions using phishing, credential theft, and wallet-draining techniques.

    Socket’s version histories show that the nine affected IDs were:

    The Daily Brief

    The signal, before the noise.

    Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

    One email. Everything that matters.

    Free to join. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re on the list. Your next Daily Brief is on its way.

    Firefox IDEarlier sports versionLater malicious versionbright-save-feed@tabtools.orgQuick Quick 7.4.0Rabbit For Desktop 8.20.10swift-clip-link@fasttools.coDial Open Pro 7.23.25Web3 & EVM 9.50.10deep-tip-sharp@browsify.coQuick Shield 5.7.1Rby-WALLEТ 6.7.10bolt-save-vault@devplugs.coLite Swatch 6.5.21🐇abby-WALLEТ 7.10.10core-note-nova@webtools.netKey Pulse 8.1.21RABB-Walleť 8.22.30gear-save-tip@extrakits.exampleTimer Pulse 5.5.5Rabbit WALLЕТ 11.10.10flex-lab-save@foxplugin.coTrack Quick 6.10.24RabbWALLЕТ 7.10.30/8.10.30pure-net-snap@fasttools.coStore Plus 8.3.18Rabb🐇WALLЕТ 9.11.30fast-zip-true@smartext.coPomodoro Plus 9.13.24RABB-WALLEТ 10.20.10

    Socket said several campaign add-ons were still live when it reported them to Mozilla. Its report noted that the remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication.

    Related Reading

    Top-ranked Chrome ‘wallet’ sneakily steals crypto seedphrases

    What affected crypto users should do

    The 40 malicious identities used distinct attack paths. Seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data.

    A recovery phrase or private key can restore a wallet elsewhere, and a serialized keyring similarly exposes the wallet’s account state before encryption can protect it.

    Anyone who entered one of those secrets, or used an affected build that transmitted its keyring, should move remaining assets to a fresh crypto wallet created from a new recovery phrase.

    Users exposed only to the credential-and-clipboard group should change affected passwords, terminate active sessions where possible, and verify copied destination addresses. Wallet keys need rotation when wallet-secret or keyring exposure occurred.

    Mozilla says it uses automated risk indicators and human review to identify malicious wallet add-ons, and advises users to install only extensions linked from the wallet provider’s official site.

    Socket documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a campaign loss total.



    Source link

    Binance
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    CryptoExpert
    • Website

    Related Posts

    Trending Cryptos

    Google Gemini AI Predicts Most Likely Bitcoin Price by Christmas 2026

    August 25, 2026
    Trending Cryptos

    The Next Phase of Tokenization Is Utility

    August 24, 2026
    Trending Cryptos

    Dario Amodei Claude AI Predicts Solana Could Be Heading for a Bigger Comeback Than Expected

    August 23, 2026
    Trending Cryptos

    Solana Governance Proposals Target Fee Burns And Faster Disinflation

    August 22, 2026
    Trending Cryptos

    Zcash miner buys 9.4% of merger target that warns failed deal could end in liquidation

    August 21, 2026
    Trending Cryptos

    Elon Musk Grok AI Just Made a Surprisingly Bullish XRP Price Predicts

    August 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Recommended
    Editors Picks

    Tom Lee Predicts Ethereum Will Lead Tokenization and AI Growth

    August 26, 2026

    Standard Chartered to Distribute Hong Kong Stablecoin

    August 26, 2026

    40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools

    August 26, 2026

    Soluna’s 1 billion-share proposal exposes the funding challenge behind its AI and Bitcoin expansion

    August 26, 2026
    Latest Posts

    We are a leading platform dedicated to delivering authoritative insights, news, and resources on cryptocurrencies and blockchain technology. At Crypto Go Lore News, our mission is to empower individuals and businesses with reliable, actionable, and up-to-date information about the cryptocurrency ecosystem. We aim to bridge the gap between complex blockchain technology and practical understanding, fostering a more informed global community.

    Latest Posts

    Tom Lee Predicts Ethereum Will Lead Tokenization and AI Growth

    August 26, 2026

    Standard Chartered to Distribute Hong Kong Stablecoin

    August 26, 2026

    40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools

    August 26, 2026
    Newsletter

    Subscribe to Updates

    Get the latest Crypto news from Crypto Golore News about crypto around the world.

    Facebook Instagram YouTube
    • Contact
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    © 2026 CryptoGoLoreNews. All rights reserved by CryptoGoLoreNews.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 78,911.00
    ethereum
    Ethereum (ETH) $ 2,463.41
    tether
    Tether (USDT) $ 0.999886
    bnb
    BNB (BNB) $ 695.47
    xrp
    XRP (XRP) $ 1.44
    usd-coin
    USDC (USDC) $ 0.999903
    solana
    Solana (SOL) $ 97.09
    tron
    TRON (TRX) $ 0.337707
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.01