Skip to main content
AVOID.NET
← Offside Wallet Theft Factory1 decision on this page

Audit log

Every state-changing event for Offside Wallet Theft Factory: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-10 20:09:00Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 455,381,789
    sig
    5ivJ6oumcEok…QsNQQtSAexplorer ↗
    hash
    8rdM5bGwzmy2…jGZb6YZisha256 → base58
    verifying row…full verify ↗
    canonical bytes (15287 B) ▸
    {"actor":"system:backfill","investigation_id":"f5b1139a-f099-4e6e-968f-3fc52706e460","kind":"publish","page_slug":"offside-wallet-theft-factory","published_at":"2026-10-10T20:09:00.352Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Offside Wallet Theft Factory","sections":[{"content":"In August 2026, researchers at the security firm Socket published findings on a cluster of 77 related Firefox extension identities, of which 40 were confirmed to be malicious. The malicious extensions impersonated popular Web3 products, including OKX (using lookalikes such as '0KX WEB3' and stylized names mimicking the brand), Rabby Wallet (variants including 'RABB-WALLET' and 'Rabbit For Desktop'), and TronLink (an extension named 'trl', also marketed as 'TrooonLink'), along with generic 'Web3 Portal' and 'Crypto & EVM' branded add-ons. Socket named the cluster the 'Offside Wallet Theft Factory'. The extensions functioned as credential-harvesting tools: roughly half presented a convincing wallet import interface that captured whatever recovery phrase or private key a victim entered, while a separate set of modified Rabby Wallet builds operated normally but leaked the wallet's stored keyring data to an external server before local encryption was applied. Reporting on the campaign was corroborated by The Hacker News, Decrypt, and The Block, all of which cited Socket's research as the primary source.","heading":"Campaign Overview","severity":"critical","sources":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"credibility":2,"name":"The Hacker News: 40 Malicious Firefox Extensions Pose as Crypto Wallets","type":"news_article","url":"https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html"},{"credibility":2,"name":"Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware","type":"news_article","url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"},{"credibility":2,"name":"The Block: Over 40 fake Firefox add-ons impersonating major crypto wallets linked to active credential theft campaign","type":"news_article","url":"https://www.theblock.co/post/360903/fake-firefox-browser-extensions-steal-crypto-wallet-credentials"}]},{"content":"According to Socket's analysis of the 40 confirmed malicious extensions, exfiltration was carried out through several distinct mechanisms. Fifteen extensions sent captured recovery phrases or private keys to attacker-controlled Cloudflare Workers deployments. Seven used hardcoded links to attacker-controlled Supabase projects to remotely serve a configurable phishing page, allowing operators to change the lure without updating the extension itself. Thirteen were modified builds of the legitimate open-source Rabby Wallet that transmitted serialized keyring data over plain HTTP on port 9000 to external domains before the data was encrypted locally, meaning wallet secrets left the device in a less-protected state than in the genuine extension. The remaining five extensions captured saved credentials and clipboard contents and sent them to a hardcoded command-and-control IP address. Socket noted that the underlying platforms — Cloudflare Workers and Supabase — are legitimate services being abused, not inherently malicious infrastructure.","heading":"Exfiltration and Control Infrastructure","severity":"critical","sources":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"credibility":2,"name":"The Hacker News: 40 Malicious Firefox Extensions Pose as Crypto Wallets","type":"news_article","url":"https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html"}]},{"content":"Socket's research also identified 37 additional extension identities that it classified as deceptive and suspicious, though not confirmed to contain wallet- or credential-stealing payloads at the time of analysis. These extensions were published as unrelated utilities, primarily sports-score tracking or currency-conversion tools, and appear to share a common hardcoded credential or publishing pipeline with the confirmed malicious wallet extensions. Several outlets reported that a subset of these sports-score extensions — Decrypt cited nine, while Socket's broader count of related shells was 37 — were later updated under the same developer identity to replace their original function with wallet-stealing code, allowing the operators to inherit an existing install base and user trust built up under the innocuous original listing.","heading":"Sports-Score Shell Operation","severity":"high","sources":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"credibility":2,"name":"Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware","type":"news_article","url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"}]},{"content":"Mozilla's own add-on signing records, cited by Socket, place the campaign's active window from March 9 to August 3, 2026, based on the versions analyzed. Several of the identified extensions remained live on the official Firefox add-on store at the time Socket reported them. Socket stated that it reported the still-live extensions to Mozilla's Add-ons Operations team and described that team's response as responsive; at least one extension, '0KX WEB3', was removed before Socket's findings were published. The practical effect is that malicious wallet-impersonating extensions were available for installation from Mozilla's official store for a period of roughly five months before being comprehensively addressed, a pattern consistent with a prior, separately reported 2025 campaign on the same storefront (see below).","heading":"Mozilla Response and Exposure Window","severity":"high","sources":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"credibility":2,"name":"Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware","type":"news_article","url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"}]},{"content":"No threat actor or group has been publicly attributed to the Offside Wallet Theft Factory campaign. Socket stated that shared code, shared infrastructure, common campaign tokens, and overlapping version histories across the 77 linked identities suggest a common publishing pipeline or closely related operators, but explicitly cautioned that its evidence does not establish that a single threat actor controls every extension in the cluster. As of this writing, attribution should be treated as unresolved; any claims naming a specific actor or nationality for this campaign are not yet supported by public reporting.","heading":"Attribution","severity":"medium","sources":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"}]},{"content":"The Offside Wallet Theft Factory is not the first large-scale wallet-impersonation campaign reported on the Firefox add-on store. In July 2025, security firm Koi Security reported a separate campaign it dubbed 'FoxyWallet', involving more than 40 malicious extensions impersonating wallets including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, and others. Koi researchers said the attackers cloned the real open-source wallet codebases and inserted logic that scanned user input for strings resembling seed phrases or private keys, then exfiltrated them to attacker-controlled servers along with the victim's IP address; the listings were also padded with hundreds of fake five-star reviews to build false trust. Koi said that campaign had been active since at least April 2025 and that some fake extensions remained listed even after being reported through Mozilla's official reporting tool. Koi suggested the artifacts pointed to a Russian-speaking group but described this attribution as 'not conclusive'. Socket's 2026 campaign is reported as a distinct operation with different impersonated brands and no established link to the FoxyWallet actors, but the two episodes together indicate a recurring structural vulnerability in how the Firefox add-on store vets and monitors wallet-branded extensions.","heading":"Related Precedent: 2025 'FoxyWallet' Campaign","severity":"medium","sources":[{"credibility":2,"name":"The Hacker News: Over 40 Malicious Firefox Extensions (2025)","type":"news_article","url":"https://thehackernews.com/2025/07/over-40-malicious-firefox-extensions.html"},{"credibility":2,"name":"Decrypt: Crypto-Draining Fake Wallet Extensions Flood Firefox Store","type":"news_article","url":"https://decrypt.co/328595/crypto-draining-fake-wallet-extensions-flood-firefox-store"},{"credibility":2,"name":"The Block: Over 40 fake Firefox add-ons impersonating major crypto wallets linked to active credential theft campaign (2025)","type":"news_article","url":"https://www.theblock.co/post/360903/fake-firefox-browser-extensions-steal-crypto-wallet-credentials"}]},{"content":"Researchers' guidance for both campaigns is consistent: anyone who entered a wallet recovery phrase or private key into one of the identified extensions should treat that phrase or key as fully compromised, because uninstalling the extension does not revoke or undo data already transmitted to attacker infrastructure. The recommended remediation is to move all funds associated with the exposed wallet to a newly generated wallet with a fresh seed phrase, rather than relying on the compromised wallet going forward. Because the extensions were distributed through Mozilla's official, signed add-on store rather than through sideloading or phishing links, standard advice to 'only install from official stores' did not protect affected users in this case.","heading":"Risk to Users and Recommended Action","severity":"critical","sources":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"credibility":2,"name":"Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware","type":"news_article","url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"}]}],"sources_used":[{"credibility":2,"name":"Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft","type":"research","url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"credibility":2,"name":"The Hacker News: 40 Malicious Firefox Extensions Pose as Crypto Wallets","type":"news_article","url":"https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html"},{"credibility":2,"name":"Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware","type":"news_article","url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"},{"credibility":2,"name":"The Block: Over 40 fake Firefox add-ons impersonating major crypto wallets linked to active credential theft campaign","type":"news_article","url":"https://www.theblock.co/post/360903/fake-firefox-browser-extensions-steal-crypto-wallet-credentials"},{"credibility":2,"name":"The Hacker News: Over 40 Malicious Firefox Extensions (2025, FoxyWallet)","type":"news_article","url":"https://thehackernews.com/2025/07/over-40-malicious-firefox-extensions.html"},{"credibility":2,"name":"Decrypt: Crypto-Draining Fake Wallet Extensions Flood Firefox Store (2025)","type":"news_article","url":"https://decrypt.co/328595/crypto-draining-fake-wallet-extensions-flood-firefox-store"}],"summary":"Offside Wallet Theft Factory is the name security firm Socket gave to a cluster of 77 related Firefox add-on identities, 40 of which it confirmed as malicious, that impersonated crypto wallets including OKX, Rabby Wallet, and TronLink to steal seed phrases, private keys, and other wallet secrets. The campaign was active on Mozilla's official add-on store from at least March 2026 through August 2026, with exfiltration carried out via Cloudflare Workers, Supabase-hosted phishing pages, and hardcoded command-and-control servers; no threat actor has been attributed. It follows a similar, separately attributed 2025 campaign ('FoxyWallet', reported by Koi Security) that impersonated Coinbase, MetaMask, and Trust Wallet, indicating a recurring attack pattern against the Firefox add-on store.","timeline":[{"date":"2025-04","event":"Koi Security says a separate, earlier campaign ('FoxyWallet') impersonating Coinbase, MetaMask, Trust Wallet and other wallets begins appearing on the Firefox add-on store.","source":"The Hacker News","source_url":"https://thehackernews.com/2025/07/over-40-malicious-firefox-extensions.html"},{"date":"2025-07","event":"Koi Security publishes research on the 'FoxyWallet' campaign, identifying more than 40 malicious Firefox extensions impersonating major crypto wallets.","source":"The Block","source_url":"https://www.theblock.co/post/360903/fake-firefox-browser-extensions-steal-crypto-wallet-credentials"},{"date":"2026-03","date_evidence":"Mozilla signing records place the campaign from March 9 to August 3,","date_original":"2026-03-09","event":"Mozilla's add-on signing records show the earliest analyzed version in the Offside Wallet Theft Factory cluster was signed, marking the start of the campaign's active window.","source":"Decrypt, citing Socket research","source_url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"},{"date":"2026-08","date_evidence":"Mozilla signing records place the campaign from March 9 to August 3,","date_original":"2026-08-03","event":"Mozilla's add-on signing records show the latest analyzed version in the cluster was signed, marking the end of the window covered by Socket's initial analysis.","source":"Decrypt, citing Socket research","source_url":"https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware"},{"date":"2026-08","event":"Socket publishes research identifying 40 confirmed malicious Firefox extensions (within a cluster of 77 linked identities) impersonating OKX, Rabby Wallet, TronLink and other Web3 products, naming the cluster the 'Offside Wallet Theft Factory'.","source":"Socket","source_url":"https://socket.dev/blog/firefox-crypto-wallet-theft"},{"date":"2026-08-20","date_evidence":"Aug 20, 2026","event":"The Hacker News reports on Socket's findings, widening coverage of the campaign.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 50f6cf14-b418-4c59-9a86-82cc25a37857
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.