Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Around the world, people are rejecting divisive and dangerous politics. We can – and must – build on that | Gordon Brown

    August 26, 2026

    Trump sends Saudi civil nuclear agreement to Congress for review

    August 26, 2026

    Drohnen, Drohungen, Deutschland – POLITICO

    August 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Around the world, people are rejecting divisive and dangerous politics. We can – and must – build on that | Gordon Brown
    • Trump sends Saudi civil nuclear agreement to Congress for review
    • Drohnen, Drohungen, Deutschland – POLITICO
    • Conservative Media Personality Makes Runoff for Alaska Governor
    • Android’s motion sickness feature is rolling out – how to see if you have it
    • Hackers abuse npm mirrors to host phishing redirect pages
    • 40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools
    • NASA’s Pandora Mission Begins Study of Exoplanets, Host Stars
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 26, 2026 Crypto & Blockchain No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Software supply-chain security firm Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto, including nine that had previously distributed sports-score tools under the same IDs.

    Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions must treat that wallet as compromised because uninstalling the add-on cannot revoke an exposed secret.

    The Aug. 19 report linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious behavior. The other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload.

    The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July.

    Infographic showing 77 linked Firefox add-on IDs split into 40 malicious and 37 deceptive sports shells, with nine IDs repurposed and separate remediation for crypto wallet-secret and credential exposure.
    Infographic showing 77 Firefox wallet extension IDs, including 40 confirmed malicious extensions using phishing, credential theft, and wallet-draining techniques.

    Socket’s version histories show that the nine affected IDs were:

    The Daily Brief

    The signal, before the noise.

    Start your day with the crypto stories moving markets, decoded by CryptoSlate’s editors.

    One email. Everything that matters.

    Free to join. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re on the list. Your next Daily Brief is on its way.

    Firefox ID Earlier sports version Later malicious version
    bright-save-feed@tabtools.org Quick Quick 7.4.0 Rabbit For Desktop 8.20.10
    swift-clip-link@fasttools.co Dial Open Pro 7.23.25 Web3 & EVM 9.50.10
    deep-tip-sharp@browsify.co Quick Shield 5.7.1 Rby-WALLEТ 6.7.10
    bolt-save-vault@devplugs.co Lite Swatch 6.5.21 🐇abby-WALLEТ 7.10.10
    core-note-nova@webtools.net Key Pulse 8.1.21 RABB-Walleť 8.22.30
    gear-save-tip@extrakits.example Timer Pulse 5.5.5 Rabbit WALLЕТ 11.10.10
    flex-lab-save@foxplugin.co Track Quick 6.10.24 RabbWALLЕТ 7.10.30/8.10.30
    pure-net-snap@fasttools.co Store Plus 8.3.18 Rabb🐇WALLЕТ 9.11.30
    fast-zip-true@smartext.co Pomodoro Plus 9.13.24 RABB-WALLEТ 10.20.10

    Socket said several campaign add-ons were still live when it reported them to Mozilla. Its report noted that the remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication.

    Related Reading

    Top-ranked Chrome ‘wallet’ sneakily steals crypto seedphrases

    What affected crypto users should do

    The 40 malicious identities used distinct attack paths. Seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data.

    A recovery phrase or private key can restore a wallet elsewhere, and a serialized keyring similarly exposes the wallet’s account state before encryption can protect it.

    Anyone who entered one of those secrets, or used an affected build that transmitted its keyring, should move remaining assets to a fresh crypto wallet created from a new recovery phrase.

    Users exposed only to the credential-and-clipboard group should change affected passwords, terminate active sessions where possible, and verify copied destination addresses. Wallet keys need rotation when wallet-secret or keyring exposure occurred.

    Mozilla says it uses automated risk indicators and human review to identify malicious wallet add-ons, and advises users to install only extensions linked from the wallet provider’s official site.

    Socket documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a campaign loss total.

    addons began Crypto Firefox Malicious sportsscore targeted Tools Wallets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Soluna’s 1 billion-share proposal exposes the funding challenge behind its AI and Bitcoin expansion

    Phantom’s plan to drop Sui exposes the hidden power wallet interfaces hold over user funds

    XRP Hot Streak Cools as Traders Hit a Wall: Where Does It Go Next?

    Cardano Committee Vote Nears Sept. 1 Deadline

    Bitcoin’s 7 million coin quantum problem just reached the US Treasury

    Elon Musk’s SpaceX Plans $100 Billion Louisiana Spaceport

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Around the world, people are rejecting divisive and dangerous politics. We can – and must – build on that | Gordon Brown

    August 26, 2026

    Trump sends Saudi civil nuclear agreement to Congress for review

    August 26, 2026

    Drohnen, Drohungen, Deutschland – POLITICO

    August 26, 2026

    Conservative Media Personality Makes Runoff for Alaska Governor

    August 26, 2026
    Latest Posts

    Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    ECB wage tracker at 2.7% in Q1 2027, indicating stable negotiated wage pressures

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Around the world, people are rejecting divisive and dangerous politics. We can – and must – build on that | Gordon Brown

    August 26, 2026

    Trump sends Saudi civil nuclear agreement to Congress for review

    August 26, 2026

    Drohnen, Drohungen, Deutschland – POLITICO

    August 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.