# Wallet Theft Moves to the Distribution Layer

Attackers keep shifting from protocol code to the software supply chain that reaches users, including extension stores, update channels and device firmware, so losses increasingly originate in components that passed review before the malicious payload existed.

- Conviction: 44 / 100 (weakening)
- Horizon: Emerging (watchlist)
- Tracking since: 2026-08-26T00:00:00.000Z
- Last updated: 2026-08-28T06:23:07.647Z
- Canonical: https://polylog.news/crypto/trends/browser-extension-wallet-supply-chain
- Publisher: Polylog
- Affected regions: Global

## Recent score history

- 2026-08-27: 46
- 2026-08-28: 44

## Recent evidence

- [confirms] Security Roundup: Governance Takeover, Hot-Wallet Drain and 40 Malicious Firefox Extensions (2026-08-27): Researchers identified a campaign of 40 malicious Firefox extensions built to harvest recovery phrases, alongside a $7.9 million hot-wallet drain at Coinsbuy attributed to key or admin compromise. The theft vector is again the distribution channel reaching users rather than protocol code, and store-reviewed extensions turning malicious is the review-then-payload pattern the thesis describes.
- [confirms] Forty malicious Firefox add-ons harvested wallet keys, and nine of them started as sports-score tools (2026-08-26): Socket linked 77 extension identities and forty malicious Firefox add-ons to a single campaign running since March, with nine starting as legitimate sports-score tools and theft code arriving only in later updates that Mozilla's review had already approved. This is the update-channel failure mode at industrial scale: the reviewed artifact was clean, so store vetting provided no protection at the moment the payload shipped.
