Offside Wallet Theft Factory: 15 Malicious Firefox Extensions Steal Crypto Secrets via Cloudflare Workers
A sophisticated campaign dubbed 'Offside Wallet Theft Factory' has been uncovered, utilizing 15 malicious Firefox extensions to exfiltrate cryptocurrency wallet secrets by abusing Cloudflare Workers.

Cybersecurity researchers have identified a widespread and persistent campaign, provisionally named "Offside Wallet Theft Factory," that leverages malicious Firefox browser extensions to steal cryptocurrency wallet secrets. The operation, active since at least March 2026, has deployed a total of 77 Firefox extension identities, with 40 confirmed as malicious and an additional 37 serving as deceptive "sports-score shells" to mask the attackers' activities and facilitate brand rotation. This campaign highlights a significant risk for cryptocurrency users who rely on browser add-ons for managing their digital assets.
Fifteen of the identified malicious extensions directly embed fake wallet interfaces or modify existing wallet code within their signed packages. These extensions are designed to capture recovery phrases (12-word and 24-word) and private keys during the wallet creation or import process. Once captured, this sensitive information is exfiltrated to attacker-controlled Cloudflare Workers deployments, a tactic that abuses legitimate cloud infrastructure to conceal malicious operations. This method allows attackers to gain full control over a victim's cryptocurrency wallet.
Several variants of these malicious extensions were found to mimic or alter code derived from the popular Rabby wallet, but they were disguised under unrelated, theme-style names. Beyond directly intercepting recovery phrases, other malicious extensions presented counterfeit import pages for well-known wallets like Portal and OKX, or generic Web3 import interfaces. These fake pages tricked users into manually typing their secret recovery phrases or private keys, which were then transmitted to the attackers. The effectiveness of this social engineering tactic is amplified by the trust users place in seemingly functional browser tools.
The campaign also employs a more stealthy approach with a separate group of 13 modified Rabby-style extensions. These extensions alter the wallet software's code to send serialized keyring data to hardcoded HTTP servers *before* the data is encrypted and saved locally. This means that standard local encryption provides no protection for the stolen information, as it is already compromised and transmitted to the attackers.
Further expanding the campaign's reach, seven extensions adopted a remote-control design powered by attacker-managed Supabase projects. One notable example, "0KX WEB3," advertised wallet functionalities but contained none, instead loading a remote website that prompted users to create or import a wallet. This staged approach, where an extension can switch between harmless and malicious content without requiring a re-release, makes detection and review significantly more challenging.
In addition to wallet theft, other malicious extensions collected user credentials and clipboard contents via hardcoded command-and-control servers. Clipboard theft is particularly dangerous as it can expose copied passwords, authentication tokens, wallet addresses, and private keys. The researchers also noted that 37 of the extensions were repackaged sports-score applications, with nine of these malicious identities having previously served as sports-score tools before being repurposed for crypto theft.
The "Offside Wallet Theft Factory" campaign underscores the critical need for users to exercise extreme caution with browser extensions, especially those related to financial activities. Researchers advise users to remove any identified malicious extensions, meticulously review add-ons after every update, and verify publisher authenticity through official project channels before installation. It is crucial never to enter recovery phrases or private keys into browser popups or webpages. If a user has entered such sensitive information into a suspect extension, they should immediately treat their wallet as compromised, transfer any remaining assets to a newly created wallet, and reset any exposed credentials.
This operation is a stark reminder of the evolving tactics employed by cybercriminals to target the lucrative cryptocurrency market. By abusing legitimate cloud services like Cloudflare Workers and exploiting user trust in browser extensions, attackers can conduct sophisticated theft operations with a degree of anonymity and scalability. The dynamic nature of this campaign, with its ability to rotate brands and infrastructure, presents an ongoing challenge for security researchers and platform providers alike.
This latest report expands the scope of the 'Offside Wallet Theft Factory' campaign to include a total of 40 malicious Firefox extensions, up from the previously reported 15. The analysis reveals that these extensions not only exfiltrate wallet secrets via Cloudflare Workers but also include modifications to Rabby Wallet builds and capture clipboard data through hard-coded C2 infrastructure. Furthermore, the campaign is noted to have involved 77 add-ons in total, with 37 others exhibiting deceptive functionality related to sports scores, suggesting a broader, coordinated effort.