Executive Summary
In March 2026, threat actors launched the 'Offside Wallet Theft Factory' campaign, deploying 40 malicious Firefox browser extensions that masqueraded as legitimate Web3 products including OKX, Rabby Wallet, and TronLink. The extensions employed sophisticated techniques including remote switches via Supabase projects, credential exfiltration through Cloudflare Workers, and clipboard monitoring to steal cryptocurrency wallet secrets, private keys, and recovery phrases. Many extensions initially appeared as benign sports score utilities before being repurposed into wallet-stealing malware under the same Firefox IDs, demonstrating advanced operational security to evade detection.
This incident highlights the growing sophistication of cryptocurrency-focused threats as digital asset adoption accelerates across enterprises and individual users, with attackers increasingly targeting browser extension ecosystems to bypass traditional security controls.
Why This Matters Now
With Web3 and cryptocurrency adoption surging in enterprise environments, browser-based attacks targeting digital wallets represent a critical blind spot in traditional security architectures, requiring enhanced egress filtering and application-level controls.
Attack Path Analysis
Attackers compromised users through malicious Firefox extensions masquerading as legitimate Web3 wallet products, establishing persistence via browser-based access to capture wallet credentials and private keys. The extensions used remote switches via Supabase and Cloudflare Workers to dynamically load phishing content and exfiltrate cryptocurrency wallet secrets to threat actor-controlled infrastructure, resulting in direct financial theft from compromised wallets.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Users installed malicious Firefox extensions from official marketplace that masqueraded as legitimate OKX, Rabby Wallet, TronLink and other Web3 products
MITRE ATT&CK® Techniques
Browser Extensions
Steal Web Session Cookie
Credentials from Web Browsers
Masquerading
Exfiltration Over C2 Channel
Spearphishing Link
Client Configurations
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Development Security
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02(b)
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Application Security Pillar
Control ID: Application Security
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Critical exposure to infostealer threats targeting cryptocurrency wallets, with malicious Firefox extensions stealing private keys and recovery phrases from financial platforms.
Computer Software/Engineering
Browser extension ecosystem compromised by threat actors using sports score shells and remote switches to deploy wallet-stealing malware across development platforms.
Internet
Web3 infrastructure targeted through counterfeit browser extensions masquerading as legitimate wallet services, exploiting cloud workers for credential exfiltration operations.
Computer/Network Security
Security practitioners must address egress filtering gaps and implement enhanced threat detection for browser-based attacks targeting cryptocurrency wallet credentials and private keys.
Sources
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secretshttps://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.htmlVerified
- Firefox Crypto Wallet Theft Campaign Analysishttps://socket.dev/blog/firefox-crypto-wallet-theftVerified
- Mozilla Firefox Add-ons Security Guidelineshttps://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Security_best_practicesVerified
- CISA Browser Extension Security Recommendationshttps://www.cisa.gov/news-events/alerts/2024/02/28/cisa-releases-guidance-browser-extension-securityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would reduce the scope and blast radius of this browser-based cryptocurrency theft by constraining lateral movement across Web3 infrastructure and limiting egress paths for credential exfiltration. While the initial compromise through malicious extensions would likely still occur, segmented access controls would constrain the attacker's ability to reach multiple wallet systems and restrict data exfiltration channels.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial browser compromise would likely still occur, but CNSF visibility would provide enhanced monitoring of suspicious extension behavior and network communications from compromised endpoints to cloud-hosted Web3 services
Control: Zero Trust Segmentation
Mitigation: Browser privilege escalation would likely still occur, but zero trust segmentation would constrain the extension's ability to access segregated Web3 services and limit cross-application wallet enumeration across different security zones
Control: East-West Traffic Security
Mitigation: Cross-platform wallet enumeration would likely be constrained through east-west traffic controls that limit compromised sessions from accessing multiple segregated Web3 application environments and blockchain service tiers
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be detected and constrained through multicloud visibility that monitors suspicious traffic patterns to Supabase and Cloudflare Workers from compromised browser sessions
Control: Egress Security & Policy Enforcement
Mitigation: Credential exfiltration would likely be constrained through egress controls that limit data transmission from Web3 environments to unauthorized external destinations including threat actor-controlled Cloudflare Workers infrastructure
Financial impact would likely be reduced in scope due to segmentation limiting cross-platform access, though individual wallets accessed before containment could still face cryptocurrency theft with constrained overall exposure
Impact at a Glance
Affected Business Functions
- Cryptocurrency Asset Management
- Digital Wallet Operations
- Web3 Transaction Processing
- Private Key Security
Estimated downtime: N/A
Estimated loss: N/A
Recovery phrases, private keys, wallet credentials, and serialized keyrings from cryptocurrency wallets including OKX, Rabby Wallet, and TronLink users. Clipboard data and authentication credentials also compromised through 40 confirmed malicious Firefox extensions.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to Supabase and Cloudflare Workers used for C2 communication
- • Deploy Cloud Firewall (ACF) with URL filtering to prevent access to malicious extension repositories and phishing infrastructure
- • Enable Multicloud Visibility & Control to detect anomalous browser extension traffic patterns and suspicious automation behaviors
- • Establish Zero Trust Segmentation with least privilege policies to limit browser extension access to sensitive wallet applications and data
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal Web3 application usage and alert on credential harvesting activities



