Return to Threats

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

thehackernews.com 2026-08-20 malicious AI use High

What Happened

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to

Why It Matters

Reported facts: Threat researchers uncovered 40 malicious Firefox extensions, masquerading as popular Web3 wallet products such as OKX, Rabby Wallet, and TronLink, that are designed to steal cryptocurrency wallet secrets as part of a broader campaign involving 77 related add-ons. These extensions share source code and infrastructure overlaps, indicating a coordinated, scalable operation targeting browser-based crypto users. RealGround analysis: Although the article focuses on browser extensions rather than AI systems, it highlights a broader software supply chain risk relevant to AI-enabled applications, where malicious code can infiltrate user environments via trusted distribution channels. Organizations deploying AI agents in browsers or integrating Web3/crypto capabilities should harden their extension and plugin ecosystems, maintain SBOMs, and establish vetting and monitoring processes to prevent similar malicious components from compromising user credentials or AI-driven workflows.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html

Talk to AI CISO