Security Hub

40 Malicious Firefox Add-ons Hit Crypto Wallets, 9 Posed as Sports Tools

Published: Aug 26, 2026By Aleksandar Dukic

Key Analysis

Security firm Socket flagged 40 malicious Firefox add-ons aimed at crypto wallets. Nine started as sports-score tools before an update turned them hostile.

40 Malicious Firefox Add-ons Hit Crypto Wallets, 9 Posed as Sports Tools

Listen To This Article

40 Malicious Firefox Add-ons Hit Crypto Wallets, 9 Posed as Sports Tools

4m 11s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Security firm Socket identified 40 malicious Firefox add-ons built to compromise crypto wallets, and nine of them started life as ordinary sports-score tools before a later update flipped them hostile. The finding was reported by CryptoSlate and shared through the outlet's verified account on August 26, 2026. Socket confirmed 40 malicious extension IDs and warned that users who installed any of them still need to migrate exposed wallet secrets even after the add-on is gone.

The detail that makes this campaign hard to catch is the delay. Nine add-ons passed review and behaved as advertised, checking live scores and standings, until an update pushed the malicious payload. Users who installed a clean tool weeks earlier never re-inspected it. The browser applied the update quietly in the background, which is how extensions are supposed to work.

The trust that extensions borrow

Browser add-ons run inside the same session as every site you visit, including your wallet. When an extension asks for permission to read page content or interact with a wallet interface, most people approve it once and forget. A sports-score tool asking to run on all pages does not raise an alarm the way a wallet clone would. That is the gap this campaign used.

Once the update lands, the code can watch for wallet activity, read what a page renders, and lift secrets such as seed phrases or private keys as they pass through the browser. For anyone spending from a browser-based self-custody wallet, that exposure reaches straight to the funds. There is no custodian to freeze the account or reverse the transfer.

Removal does not undo the leak

Socket's warning is blunt on the recovery step: pulling the add-on stops future collection, but it does not restore safety for keys that already left the device. A private key or recovery phrase that touched a compromised browser has to be treated as public. The only real fix is to move funds to a freshly generated wallet whose secret has never been near the infected profile, then abandon the old one.

That is the key-rotation trap. People assume that deleting the bad extension closes the door, so they leave assets in the same wallet. The credential is the thing that was stolen, not the extension, and the credential keeps working for the attacker until the wallet is drained or emptied by the owner first.

Anyone who ran one of the flagged add-ons should audit installed Firefox extensions now, remove anything unfamiliar, and generate a new wallet if a browser-stored key or seed phrase was ever entered while a suspect tool was active. Hardware signing helps here because the private key never enters the browser at all. Cards and wallets that keep signing on a separate device, rather than in the extension, sit outside this specific attack path.

A recurring pattern in extension stores

Malware that arrives through a delayed update is not new, and it keeps working because store review checks the version submitted, not the version pushed months later. The sports-score disguise is simply a category that draws steady installs and rarely gets a second look. Socket has tracked similar supply-side tricks across package registries and browser stores, where a benign first release earns trust that a later version spends.

For crypto users the takeaway is narrow and practical. Treat every browser extension with wallet-adjacent permissions as a live risk surface, not a one-time decision. Review what is installed on a schedule. Keep large balances off any wallet that lives entirely inside a browser profile, and lean on separate-device signing for the funds you actually spend. The people caught by this campaign did nothing dramatic. They installed a working tool and let it update.

Overview

Socket flagged 40 malicious Firefox add-ons targeting crypto wallets, nine of which began as legitimate sports-score tools before a later update turned them into credential thieves. Removing an affected add-on stops new theft but does not protect keys already exposed; those wallets must be rebuilt from scratch. The episode is a reminder that extension permissions are a standing risk, not a one-time approval, and that hardware-backed signing keeps private keys out of the browser where this kind of malware operates.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.