TLDR
- Researchers found 77 Firefox extensions linked to a coordinated wallet theft operation.
- 40 of the extensions directly steal crypto wallet secrets or login credentials.
- 37 extensions use fake sports score apps as cover for the wider network.
- Several extensions copy Rabby Wallet code to intercept recovery phrases and private keys.
- Stolen data is sent to hacker controlled servers using Cloudflare Workers and Supabase.
Security researchers at Socket say they found 77 Firefox browser extensions tied to a large scale crypto wallet theft campaign. The group has been active since at least March 2026 and was still running in August.
Of the 77 extensions, 40 were confirmed to steal wallet secrets or login credentials. The other 37 acted as sports score apps that hid the operation’s shared code and infrastructure.
How the Extensions Work
Some extensions pretend to be well known wallet tools like OKX or Rabby Wallet. One extension called 0KX WEB3 used a zero instead of the letter O to look like the real OKX brand.
This extension had no actual wallet features. Instead, it loaded a webpage stored on Supabase, a cloud hosting service, that asked users to enter their recovery phrase or private key.
Once a person types in that phrase, hackers can copy the wallet on another device and take the funds. The extension only asked for basic browser permissions, which made it look harmless.
Seven extensions used this same remote loading method. This let hackers switch the extension between a normal looking tool and a fake wallet page without updating the extension itself.
Wallet Code Was Copied and Changed
Other extensions took a different approach. Fifteen of them copied real Rabby Wallet code and changed it to capture recovery phrases during wallet setup.
These extensions worked like normal wallets on the surface. But when a person created or imported a wallet, the recovery phrase was quietly sent to a server controlled by the hackers.
Researchers found the requests included a shared code labeled EQOx7EIPZSNi, which appeared across several different extensions. This suggests the same group or tools were behind them.
Another 13 extensions targeted a different part of the wallet process. These changed how Rabby Wallet saves account data internally, sending it to a hacker server before the wallet encrypted it.
This method was harder to notice because the wallet kept working normally. Removing the extension stopped further theft, but any data already sent could not be pulled back.
Some extensions used names close to real products, like Rabb-Walӏet or RABB-Walӏet, using look alike letters to seem legitimate. Others were disguised as browser themes with names like Sady-Theme or Safe-Theme.
Researchers also found six extensions styled after a wallet called Portal, which asked users to import a wallet through a fake setup screen. These sent stolen phrases straight to a hacker run web address.
The most recent part of the investigation identified five more extensions built to steal saved passwords and clipboard data, not wallet phrases. These sent stolen information to a single server address rather than through Cloudflare or Supabase.
Researchers reported all extensions still active during their review to Mozilla’s security team. Mozilla removed several listings before the report was published.



