OKX, TronLink and Rabby Wallet: 40 Malicious Firefox Extensions Steal Crypto Wallet Recovery Phrases, Private Keys and Credentials

OKX, TronLink and Rabby Wallet: 40 Malicious Firefox Extensions Steal Crypto Wallet Recovery Phrases, Private Keys and Credentials

Malicious Firefox Extensions Steal Crypto Wallets in "Offside Wallet Theft Factory" Campaign

A large-scale cyberattack, dubbed "Offside Wallet Theft Factory," has been targeting cryptocurrency users since at least March 2026, deploying 40 malicious Firefox extensions designed to steal wallet recovery phrases, private keys, credentials, and clipboard data. The campaign leverages cloned code, deceptive listings, and fake branding to impersonate trusted Web3 platforms, including OKX, Rabby Wallet, and TronLink.

How the Attack Works

The extensions masquerade as legitimate crypto wallets but either load remote phishing pages or embed theft code directly into their packages. Key tactics include:

  • Phishing via Remote Pages: Seven extensions, such as "0KX WEB3" (a spoof of OKX Wallet), used Supabase projects to dynamically load fake wallet interfaces. Victims were tricked into entering recovery phrases or private keys during "wallet import" processes, which were then sent to attackers.
  • Direct Theft Code: Fifteen extensions, many based on modified Rabby Wallet code, captured 12- and 24-word recovery phrases during wallet creation or import, transmitting them to Cloudflare Worker endpoints. Another 13 Rabby-based variants stole unencrypted wallet keyring data before local encryption, sending it to hardcoded HTTP servers (often on port 9000).
  • Credential & Clipboard Theft: Five extensions harvested user credentials and clipboard contents, including wallet addresses, passwords, and private keys, exfiltrating data to a command-and-control server at 77[.]91[.]100[.]175.

Impact & Risks

Once stolen, a recovery phrase or private key grants attackers full control over a victim’s crypto wallet, allowing them to transfer assets without the user’s password. Removing the malicious extension does not reverse the theft, as the attacker can restore the wallet on another device.

Indicators of Compromise (IOCs)

  • Phishing URL: hxxps://portal-web3-extension-welcome[.]pages[.]dev/home
  • Supabase Project: hxxps://kyfyvuwifdukctqyggto[.]supabase[.]co (used for remote control)

Mozilla’s security team removed the malicious extensions following disclosure, but the campaign highlights the persistent threat of deceptive browser extensions in crypto theft.

Source: https://cyberpress.org/40-firefox-extensions-steal-crypto/

TRON DAO cybersecurity rating report: https://www.rankiteo.com/company/trondao

Keystone Hardware Wallet cybersecurity rating report: https://www.rankiteo.com/company/keystonehardwarewallet

OKX cybersecurity rating report: https://www.rankiteo.com/company/okxofficial

"id": "TROKEYOKX1787207046",
"linkid": "trondao, keystonehardwarewallet, okxofficial",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'FinTech / Cryptocurrency',
                        'name': 'OKX',
                        'type': 'Cryptocurrency platform'},
                       {'industry': 'FinTech / Cryptocurrency',
                        'name': 'Rabby Wallet',
                        'type': 'Crypto wallet'},
                       {'industry': 'FinTech / Cryptocurrency',
                        'name': 'TronLink',
                        'type': 'Crypto wallet'}],
 'attack_vector': ['Malicious browser extensions',
                   'Remote phishing pages',
                   'Deceptive listings'],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': ['Recovery phrases',
                                                         'Private keys'],
                 'sensitivity_of_data': 'High (enables full wallet access)',
                 'type_of_data_compromised': ['Wallet recovery phrases',
                                              'Private keys',
                                              'Credentials',
                                              'Clipboard data']},
 'date_detected': '2026-03',
 'description': 'A large-scale cyberattack targeting cryptocurrency users '
                'since at least March 2026, deploying 40 malicious Firefox '
                'extensions designed to steal wallet recovery phrases, private '
                'keys, credentials, and clipboard data. The campaign leverages '
                'cloned code, deceptive listings, and fake branding to '
                'impersonate trusted Web3 platforms, including OKX, Rabby '
                'Wallet, and TronLink.',
 'impact': {'data_compromised': ['Wallet recovery phrases',
                                 'Private keys',
                                 'Credentials',
                                 'Clipboard data'],
            'identity_theft_risk': 'High (recovery phrases/private keys enable '
                                   'wallet restoration on attacker-controlled '
                                   'devices)',
            'operational_impact': 'Full control over victim’s crypto wallet, '
                                  'enabling unauthorized asset transfers',
            'payment_information_risk': 'High (crypto wallet access)',
            'systems_affected': ['Cryptocurrency wallets']},
 'initial_access_broker': {'entry_point': 'Malicious Firefox extensions',
                           'high_value_targets': 'Cryptocurrency users'},
 'lessons_learned': 'Persistent threat of deceptive browser extensions in '
                    'crypto theft; removing malicious extensions does not '
                    'reverse theft of recovery phrases/private keys.',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'root_causes': ['Deceptive extension listings',
                                            'Cloned code impersonating '
                                            'legitimate wallets',
                                            'Remote phishing pages']},
 'recommendations': 'Users should verify extension authenticity, avoid '
                    'entering recovery phrases into browser-based interfaces, '
                    'and monitor wallet activity for unauthorized '
                    'transactions.',
 'references': [{'source': 'Incident report',
                 'url': 'hxxps://portal-web3-extension-welcome[.]pages[.]dev/home'},
                {'source': 'Supabase project (IOC)',
                 'url': 'hxxps://kyfyvuwifdukctqyggto[.]supabase[.]co'}],
 'response': {'containment_measures': 'Mozilla’s security team removed the '
                                      'malicious extensions'},
 'title': 'Offside Wallet Theft Factory Campaign',
 'type': 'Malware / Phishing'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.