← Trends

Wallet Theft Moves to the Distribution Layer

Attackers keep shifting from protocol code to the software supply chain that reaches users, including extension stores, update channels and device firmware, so losses increasingly originate in components that passed review before the malicious payload existed.

weakening · confidence 44 · Emerging (watchlist) · tracking since August 26, 2026 · updated August 28, 2026

Sign in to get threshold and movement alerts for this trend.

Score history

Daily conviction score, 0 to 100. Higher means the thesis is more strongly corroborated.

Aug 27 · 46Aug 28 · 44

Now 44 · -2 since Aug 27 · ranged 44 to 46

Showing the last few days. Unlock full score history.

Why the conviction moved

  • Aug 27
    Strengthened +6

    Researchers identified a campaign of 40 malicious Firefox extensions built to harvest recovery phrases, alongside a $7.9 million hot-wallet drain at Coinsbuy attributed to key or admin compromise. The theft vector is again the distribution channel reaching users rather than protocol code, and store-reviewed extensions turning malicious is the review-then-payload pattern the thesis describes.

  • Aug 26
    Strengthened +7

    Socket linked 77 extension identities and forty malicious Firefox add-ons to a single campaign running since March, with nine starting as legitimate sports-score tools and theft code arriving only in later updates that Mozilla's review had already approved. This is the update-channel failure mode at industrial scale: the reviewed artifact was clean, so store vetting provided no protection at the moment the payload shipped.

Source trail

  • Supporting · August 27, 2026

    Security Roundup: Governance Takeover, Hot-Wallet Drain and 40 Malicious Firefox Extensions

    Researchers identified a campaign of 40 malicious Firefox extensions built to harvest recovery phrases, alongside a $7.9 million hot-wallet drain at Coinsbuy attributed to key or admin compromise. The theft vector is again the distribution channel reaching users rather than protocol code, and store-reviewed extensions turning malicious is the review-then-payload pattern the thesis describes.

    Rekt News
  • Supporting · August 26, 2026

    Forty malicious Firefox add-ons harvested wallet keys, and nine of them started as sports-score tools

    Socket linked 77 extension identities and forty malicious Firefox add-ons to a single campaign running since March, with nine starting as legitimate sports-score tools and theft code arriving only in later updates that Mozilla's review had already approved. This is the update-channel failure mode at industrial scale: the reviewed artifact was clean, so store vetting provided no protection at the moment the payload shipped.

    CryptoSlate

Unlock full source trail, score history, and daily updates.

Unlock Trends

Affected regions & assets

RegionsGlobal
Assets2 assetsUnlock Trends

Townsquare

Argue the thesis in Townsquare.