Executive Summary

In March 2026, threat actors launched the 'Offside Wallet Theft Factory' campaign, deploying 40 malicious Firefox browser extensions that masqueraded as legitimate Web3 products including OKX, Rabby Wallet, and TronLink. The extensions employed sophisticated techniques including remote switches via Supabase projects, credential exfiltration through Cloudflare Workers, and clipboard monitoring to steal cryptocurrency wallet secrets, private keys, and recovery phrases. Many extensions initially appeared as benign sports score utilities before being repurposed into wallet-stealing malware under the same Firefox IDs, demonstrating advanced operational security to evade detection.

This incident highlights the growing sophistication of cryptocurrency-focused threats as digital asset adoption accelerates across enterprises and individual users, with attackers increasingly targeting browser extension ecosystems to bypass traditional security controls.

Why This Matters Now

With Web3 and cryptocurrency adoption surging in enterprise environments, browser-based attacks targeting digital wallets represent a critical blind spot in traditional security architectures, requiring enhanced egress filtering and application-level controls.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The extensions initially appeared as legitimate sports score utilities before being repurposed into wallet-stealing malware under the same Firefox IDs, and used remote switches via Supabase projects to dynamically serve malicious content.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would reduce the scope and blast radius of this browser-based cryptocurrency theft by constraining lateral movement across Web3 infrastructure and limiting egress paths for credential exfiltration. While the initial compromise through malicious extensions would likely still occur, segmented access controls would constrain the attacker's ability to reach multiple wallet systems and restrict data exfiltration channels.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial browser compromise would likely still occur, but CNSF visibility would provide enhanced monitoring of suspicious extension behavior and network communications from compromised endpoints to cloud-hosted Web3 services

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Browser privilege escalation would likely still occur, but zero trust segmentation would constrain the extension's ability to access segregated Web3 services and limit cross-application wallet enumeration across different security zones

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-platform wallet enumeration would likely be constrained through east-west traffic controls that limit compromised sessions from accessing multiple segregated Web3 application environments and blockchain service tiers

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications would likely be detected and constrained through multicloud visibility that monitors suspicious traffic patterns to Supabase and Cloudflare Workers from compromised browser sessions

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Credential exfiltration would likely be constrained through egress controls that limit data transmission from Web3 environments to unauthorized external destinations including threat actor-controlled Cloudflare Workers infrastructure

Impact (Mitigations)

Financial impact would likely be reduced in scope due to segmentation limiting cross-platform access, though individual wallets accessed before containment could still face cryptocurrency theft with constrained overall exposure

Impact at a Glance

Affected Business Functions

  • Cryptocurrency Asset Management
  • Digital Wallet Operations
  • Web3 Transaction Processing
  • Private Key Security
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Recovery phrases, private keys, wallet credentials, and serialized keyrings from cryptocurrency wallets including OKX, Rabby Wallet, and TronLink users. Clipboard data and authentication credentials also compromised through 40 confirmed malicious Firefox extensions.

Recommended Actions

  • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to Supabase and Cloudflare Workers used for C2 communication
  • Deploy Cloud Firewall (ACF) with URL filtering to prevent access to malicious extension repositories and phishing infrastructure
  • Enable Multicloud Visibility & Control to detect anomalous browser extension traffic patterns and suspicious automation behaviors
  • Establish Zero Trust Segmentation with least privilege policies to limit browser extension access to sensitive wallet applications and data
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal Web3 application usage and alert on credential harvesting activities

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image