Skip to content
Back to Guavy Wire
Crypto

Malicious Firefox Add-Ons Target Crypto Wallets in Massive Phishing Campaign

Share

A recent report by Socket, a software supply-chain security firm, revealed that 40 malicious Firefox add-ons targeted cryptocurrency wallets. The campaign, dubbed the 'Offside Wallet Theft Factory,' operated from at least March to August and affected 77 identities. Of these, 40 had confirmed malicious behavior, including phishing, credential theft, and wallet-draining techniques.

The nine affected add-on IDs had previously distributed sports-score tools under the same names, raising suspicions about their legitimacy. Mozilla's signing records showed that the original versions of these add-ons were submitted for review as early as March 9. However, it was not until August that the malicious behavior was confirmed.

Socket's analysis revealed that uninstalling the malicious add-ons would not be enough to revoke exposed secrets, such as recovery phrases or private keys. As a result, anyone whose wallet was compromised by one of these add-ons should treat their wallet as compromised and take necessary precautions.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc