Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
The security company Socket released research results linking 77 Firefox extensions to malicious activities they call the “Offside Wallet Theft Factory,” of which 40 have been confirmed to have malicious behavior. These extensions disguise themselves as Web3 products like OKX, Rabby Wallet, and TronLink, enticing users to import wallets by faking wallet interfaces or using modified real wallet code to steal mnemonic phrases and private keys as users input them. Mozilla’s signature records show that this activity lasted from March 9 to August 3, and multiple extensions were still online when Socket reported.About half of these extensions displayed realistic wallet interfaces and prompted users to import existing wallets, thereby intercepting the entered mnemonic phrases or private keys; another 13 were modified versions of Rabby that sent account data stored in wallets to external servers while functioning normally; and 5 specifically collected saved credentials and clipboard content. Additionally, 37 extensions disguised themselves as password generators, dark mode toggles, VPNs, currency converters, and note-taking tools, but actually ran a sports score application sharing the same hardcoded credentials. Nine confirmed malicious extensions were initially released in the form of score applications for sports like soccer and basketball, with subsequent updates replacing them with wallet theft code.Socket named this activity the “Offside Wallet Theft Factory,” but cautioned that it has not yet confirmed whether all extensions are controlled by the same operator. The Socket team stated that any user who has entered mnemonic phrases or private keys in these extensions should consider it a “permanent leak” and immediately transfer funds to a new wallet, as uninstalling the extensions cannot undo the mnemonic phrases sent elsewhere.