Wallet Theft Moves to the Distribution Layer
Attackers keep shifting from protocol code to the software supply chain that reaches users, including extension stores, update channels and device firmware, so losses increasingly originate in components that passed review before the malicious payload existed.
weakening · confidence 44 · Emerging (watchlist) · tracking since August 26, 2026 · updated August 28, 2026
Score history
Daily conviction score, 0 to 100. Higher means the thesis is more strongly corroborated.
Now 44 · -2 since Aug 27 · ranged 44 to 46
Showing the last few days. Unlock full score history.
Why the conviction moved
- Aug 27Strengthened +6
Researchers identified a campaign of 40 malicious Firefox extensions built to harvest recovery phrases, alongside a $7.9 million hot-wallet drain at Coinsbuy attributed to key or admin compromise. The theft vector is again the distribution channel reaching users rather than protocol code, and store-reviewed extensions turning malicious is the review-then-payload pattern the thesis describes.
- Aug 26Strengthened +7
Socket linked 77 extension identities and forty malicious Firefox add-ons to a single campaign running since March, with nine starting as legitimate sports-score tools and theft code arriving only in later updates that Mozilla's review had already approved. This is the update-channel failure mode at industrial scale: the reviewed artifact was clean, so store vetting provided no protection at the moment the payload shipped.
Source trail
Supporting · August 27, 2026
Security Roundup: Governance Takeover, Hot-Wallet Drain and 40 Malicious Firefox Extensions
Researchers identified a campaign of 40 malicious Firefox extensions built to harvest recovery phrases, alongside a $7.9 million hot-wallet drain at Coinsbuy attributed to key or admin compromise. The theft vector is again the distribution channel reaching users rather than protocol code, and store-reviewed extensions turning malicious is the review-then-payload pattern the thesis describes.
Rekt NewsSupporting · August 26, 2026
Forty malicious Firefox add-ons harvested wallet keys, and nine of them started as sports-score tools
Socket linked 77 extension identities and forty malicious Firefox add-ons to a single campaign running since March, with nine starting as legitimate sports-score tools and theft code arriving only in later updates that Mozilla's review had already approved. This is the update-channel failure mode at industrial scale: the reviewed artifact was clean, so store vetting provided no protection at the moment the payload shipped.
CryptoSlate
Unlock full source trail, score history, and daily updates.
Unlock TrendsAffected regions & assets
Townsquare
Argue the thesis in Townsquare.