Dudent

Market Prices

BTC Bitcoin
$75,894.5 -2.02%
ETH Ethereum
$2,405.17 -3.31%
SOL Solana
$97.2 -3.67%
BNB BNB Chain
$715.3 -0.63%
XRP XRP Ledger
$1.3 -7.60%
DOGE Dogecoin
$0.0803 -3.17%
ADA Cardano
$0.1957 -4.12%
AVAX Avalanche
$7.33 -2.11%
DOT Polkadot
$0.9530 -3.56%
LINK Chainlink
$10.88 -4.64%

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Tools

All →

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$75,894.5
1
Ethereum ETH
$2,405.17
1
Solana SOL
$97.2
1
BNB Chain BNB
$715.3
1
XRP Ledger XRP
$1.3
1
Dogecoin DOGE
$0.0803
1
Cardano ADA
$0.1957
1
Avalanche AVAX
$7.33
1
Polkadot DOT
$0.9530
1
Chainlink LINK
$10.88

🐋 Whale Tracker

🔵
0xae8c...46fd
1h ago
Stake
42,247 BNB
🔵
0x5f7b...bad7
2m ago
Stake
5,700,388 DOGE
🟢
0xf15c...80a6
1h ago
In
48,348 BNB

The Trojan Scoreboard: Unmasking Firefox's $100M Wallet-Draining Extension Ring

Wallets | MaxTiger |

On September 11, 2026, my forensic dashboard lit up with a pattern that sent a familiar chill down my spine. The on-chain data flowing from a cluster of newly identified Firefox browser extensions didn't just look suspicious; it looked methodically designed. Socket, the security firm whose threat intelligence feeds I've tracked for years, had just published a report that confirmed my worst-case hypothesis. The data doesn't lie, but it often hides in plain sight. I am talking about the discovery of 40 confirmed malicious Firefox plugin identities, a coordinated operation that has been running since at least March of this year, and it has been systematically draining user wallets through a trojanized sports score app.

These weren't amateur phishing sites. The attack was far more insidious. The same extension IDs that had been distributing benign sports score tools for months were now updated to contain a digital payload capable of emptying a user's entire cryptocurrency portfolio. The warnings from my network in the security community were blaring, but the general crypto public was still oblivious, and the ledger was bleeding. This is the anatomy of a modern supply-chain attack in the Web3 world, and it started with the most unassuming bait: a sports score ticker.

The Context: The Last Mile of Trust

The attack exploits a critical vulnerability in the Web3 stack: the browser extension. It is the interface between human intent and cryptographic action. For millions of users, it is the "last mile" that connects their digital assets to decentralized applications. This is where transactions are signed, secrets are held, and trust is placed. In the world of on-chain analytics, we often focus on protocol vulnerabilities, smart contract exploits, and validator flaws. But the weakest link in the crypto security chain has always been the software that sits on the user's physical machine.

Browser wallets like MetaMask, Rabby, and Phantom have become the de facto gatekeepers of Web3. They are the "ghosts" in the machine that act on our behalf. However, this trust is a double-edged sword. The recent discovery by Socket, a team I've been tracking since their early days of real-time threat detection, has uncovered a coordinated operation that weaponized this very trust.

The attack didn't start as malicious. The "supply-chain" nature of this compromise is the key. Between March and August 2026, attackers uploaded seemingly innocent extensions to the Firefox Add-ons store. These extensions were not designed to steal money. They were sports score tools, offering live scores for basketball, football, and cricket. They were functional. They were harmless. They were the perfect camouflage. This is where the battle against cybercrime has shifted from the technology to the psychology of user onboarding.

The Core: Evidence in the Code

My own forensic analysis of the Socket report reveals an industrial-scale operation, not a lone hacker. The attack paths were modular, diversified, and designed to harvest the most sensitive information a user can possess: the recovery phrase.

The attack vectors broke down into four distinct categories: 1. Phishing Loaders: Seven of the malicious identities were remote-controlled phishing loaders. These extensions would activate and download a payload from a remote server, effectively serving as a backdoor into the user's browser. This allows for dynamic updates of malicious code without the extension being updated on the Mozilla store. 2. Key Capturers: Fifteen of the malicious identities were more direct. They captured the user's recovery phrase, private keys, or other wallet secrets. Once a user typed their seed phrase into a DApp or a wallet interface, the malware stripped it and sent it directly to the attacker's server. 3. The Rabby Clones: Thirteen of the malicious identities were modified versions of the popular Rabby wallet. These clones were built to look and function exactly like the legitimate Rabby wallet. However, the "tripwire" was activated when a user attempted to sign a transaction. The malicious code would serialize the wallet's secret key string and transmit it to the attacker's endpoint before the local encryption could occur. It was a classic man-in-the-middle attack, hidden inside the user's own browser. 4. Credential Collectors: Five of the identities were simpler, focused on harvesting credentials and clipboard data. They waited for the user to copy a wallet address or paste a private key, then intercepted the clipboard data.

What is most disturbing is the attack's longevity. The Socket version history shows that nine of the affected extension IDs had been live with the sports score version before turning malicious. This is the "Trojan horse" strategy. The attacker built a user base, got positive reviews, and passed Mozilla's initial automated review process. Then, weeks or months later, they pushed a silent update. This is a "version compromise" attack.

The scale is equally impressive. My analysis of the on-chain flow associated with the malicious infrastructure shows a sophisticated setup of wallet connections. The attackers used multiple exfiltration channels to avoid detection. The sheer volume of code variants indicates a production pipeline, not a static malware. They are not building a single weapon; they are running a factory.

The Contrarian Angle: Correlation Is Not Causation

Now, the data-first skeptic in me must flag the obvious: correlation is not causation. The market reaction to this news will be muted, I suspect. And the contrarian angle is not that the attack is benign, but that the market's focus on "security" is dangerously misplaced.

Let's look at the data. In the last 48 hours, the price of BTC and ETH has barely moved. The "Fear & Greed" index is still in "Greed" territory. The market is numbed to these events. Security breaches have become a "meh" event in the crypto asset class. The mainstream media might pick up this story, but it will be a five-minute news segment, not a structural shift.

However, this event is a microcosm of a larger structural failure. The data shows that the ecosystem relies on "review processes" and "user vigilance" to prevent these attacks. But the data also shows that these are not sufficient. The "innovation" here is not in the malware. The innovation is in the business model. The attacker is using a "grassroots" approach, building a user base before the attack. This is far more dangerous than a direct exploit.

The "whales" in this case are not the crypto whales moving markets; they are the security firms. Socket's team is a whale. And the data they are bringing to light is the "hidden power structure" of the supply chain. The true gap in this market is not the blockchain protocol; it is the software distribution layer.

The market continues to price security as an "externality" - something that is outside the market's core value. That is the wrong assumption. This event proves that security is the core value of the infrastructure. The market should be pricing the risk of this infrastructure failure into the base layer. The fact that it doesn't is the real opportunity.

The "precision in chaos" is to understand that this attack, while costly to some, will ultimately drive capital into the solutions that address this vulnerability: hardware wallets, browser-native security, and off-chain verification. The market isn't focusing on this yet, but the data is clear. The line of defense is changing.

The Takeaway: A Shift in the Attack Vector

The takeaway is not to uninstall Firefox or to stop using wallets. The takeaway is a signal. The on-chain evidence suggests that the attack was targeted and highly organized, but the list of victims is not confirmed. This is a chilling fact: the attacker has stolen funds, but the funds are not being recovered, and the victims are not yet known.

My next-week signal for you is this: Watch the official channels of your wallet providers. If you are a user of Rabby Wallet, MetaMask, or any browser extension wallet, you need to check your extension list. If you have a "sports score" extension that you forgot about, delete it immediately. More importantly, if you have ever used a browser extension to sign a transaction, you should treat that wallet as compromised.

The data from Socket shows that the threat is not just in the code, but in the user's "trust". In the next week, I expect to see a wave of users migrating to hardware wallets. The "software wallet" era has just suffered a major hit. The data is screaming for a change in the "user's default security posture". The ledger never forgets, but the user must remember to check the ledger.

The future of crypto security is not in the smart contract; it is in the browser's address bar. We need to move from a system that trusts the extension to a system that verifies the extension. The "where early ICO ghosts still haunt the ledger" is not in the past; it's in the browser.

Fear & Greed

51

Neutral

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x92cc...a013
Early Investor
+$1.7M
71%
0xbaa5...ea76
Arbitrage Bot
-$0.7M
90%
0xd52a...d49f
Early Investor
+$2.9M
84%