The post ‘Crypto Copilot’ Extension Sends SOL to Hacker: Details appeared on BitcoinEthereumNews.com. According to a recent report, the “Crypto Copilot” Chrome extension is siphoning SOL from anyone who installs it. The extension pretends to be a trading helper for Solana users, letting you execute swaps directly from X (Twitter) posts.  On the surface, it looks totally normal: it connects to standard wallets, shows DexScreener price data, and routes swaps through Raydium, Solana’s biggest AMM. But underneath that UI, it secretly injects an extra instruction into every transaction you sign. How it works  The extension quietly attaches a second instruction behind the scenes: a tiny, hidden SOL transfer to the attacker’s personal wallet. You never see it in the UI. Wallets like Phantom only show a summary unless you manually expand the instruction list. So most users never notice an outbound transfer buried inside the same transaction. The fee-extraction code itself is simple: it calculates either a tiny fixed fee or a tiny percentage of the trade, converts it to lamports, and then quietly adds a second instruction to the transaction that sends that amount to the attacker’s wallet.  What makes it dangerous is that this logic is buried inside heavily obfuscated JavaScript. On the surface, the UI looks completely legitimate, showing only the expected Raydium swap.  The extension also connects to a backend domain with a typo, which records wallet IDs, tracks activity, and pretends to provide “points” and referrals even though the actual website is empty and non-functional.  On-chain, the theft looks like tiny, ordinary SOL transfers sitting next to legitimate swaps. Hence, unless someone inspects instructions carefully or knows the attacker’s address, it blends in.. The fee is intentionally small enough to be ignored in the moment. Source: https://u.today/crypto-copilot-extension-sends-sol-to-hacker-detailsThe post ‘Crypto Copilot’ Extension Sends SOL to Hacker: Details appeared on BitcoinEthereumNews.com. According to a recent report, the “Crypto Copilot” Chrome extension is siphoning SOL from anyone who installs it. The extension pretends to be a trading helper for Solana users, letting you execute swaps directly from X (Twitter) posts.  On the surface, it looks totally normal: it connects to standard wallets, shows DexScreener price data, and routes swaps through Raydium, Solana’s biggest AMM. But underneath that UI, it secretly injects an extra instruction into every transaction you sign. How it works  The extension quietly attaches a second instruction behind the scenes: a tiny, hidden SOL transfer to the attacker’s personal wallet. You never see it in the UI. Wallets like Phantom only show a summary unless you manually expand the instruction list. So most users never notice an outbound transfer buried inside the same transaction. The fee-extraction code itself is simple: it calculates either a tiny fixed fee or a tiny percentage of the trade, converts it to lamports, and then quietly adds a second instruction to the transaction that sends that amount to the attacker’s wallet.  What makes it dangerous is that this logic is buried inside heavily obfuscated JavaScript. On the surface, the UI looks completely legitimate, showing only the expected Raydium swap.  The extension also connects to a backend domain with a typo, which records wallet IDs, tracks activity, and pretends to provide “points” and referrals even though the actual website is empty and non-functional.  On-chain, the theft looks like tiny, ordinary SOL transfers sitting next to legitimate swaps. Hence, unless someone inspects instructions carefully or knows the attacker’s address, it blends in.. The fee is intentionally small enough to be ignored in the moment. Source: https://u.today/crypto-copilot-extension-sends-sol-to-hacker-details

‘Crypto Copilot’ Extension Sends SOL to Hacker: Details

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

According to a recent report, the “Crypto Copilot” Chrome extension is siphoning SOL from anyone who installs it.

The extension pretends to be a trading helper for Solana users, letting you execute swaps directly from X (Twitter) posts. 

On the surface, it looks totally normal: it connects to standard wallets, shows DexScreener price data, and routes swaps through Raydium, Solana’s biggest AMM.

But underneath that UI, it secretly injects an extra instruction into every transaction you sign.

How it works 

The extension quietly attaches a second instruction behind the scenes: a tiny, hidden SOL transfer to the attacker’s personal wallet.

You never see it in the UI. Wallets like Phantom only show a summary unless you manually expand the instruction list. So most users never notice an outbound transfer buried inside the same transaction.

The fee-extraction code itself is simple: it calculates either a tiny fixed fee or a tiny percentage of the trade, converts it to lamports, and then quietly adds a second instruction to the transaction that sends that amount to the attacker’s wallet. 

What makes it dangerous is that this logic is buried inside heavily obfuscated JavaScript. On the surface, the UI looks completely legitimate, showing only the expected Raydium swap. 

The extension also connects to a backend domain with a typo, which records wallet IDs, tracks activity, and pretends to provide “points” and referrals even though the actual website is empty and non-functional. 

On-chain, the theft looks like tiny, ordinary SOL transfers sitting next to legitimate swaps. Hence, unless someone inspects instructions carefully or knows the attacker’s address, it blends in.. The fee is intentionally small enough to be ignored in the moment.

Source: https://u.today/crypto-copilot-extension-sends-sol-to-hacker-details

Market Opportunity
Solana Logo
Solana Price(SOL)
$87.09
$87.09$87.09
-0.57%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Share
BitcoinEthereumNews2025/09/18 02:23
Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Academic Publishing and Fairness: A Game-Theoretic Model of Peer-Review Bias

Exploring how biases in the peer-review system impact researchers' choices, showing how principles of fairness relate to the production of scientific knowledge based on topic importance and hardness.
Share
Hackernoon2025/09/17 23:15
3 Paradoxes of Altcoin Season in September

3 Paradoxes of Altcoin Season in September

The post 3 Paradoxes of Altcoin Season in September appeared on BitcoinEthereumNews.com. Analyses and data indicate that the crypto market is experiencing its most active altcoin season since early 2025, with many altcoins outperforming Bitcoin. However, behind this excitement lies a paradox. Most retail investors remain uneasy as their portfolios show little to no profit. This article outlines the main reasons behind this situation. Altcoin Market Cap Rises but Dominance Shrinks Sponsored TradingView data shows that the TOTAL3 market cap (excluding BTC and ETH) reached a new high of over $1.1 trillion in September. Yet the share of OTHERS (excluding the top 10) has declined since 2022, now standing at just 8%. OTHERS Dominance And TOTAL3 Capitalization. Source: TradingView. In past cycles, such as 2017 and 2021, TOTAL3 and OTHERS.D rose together. That trend reflected capital flowing not only into large-cap altcoins but also into mid-cap and low-cap ones. The current divergence shows that capital is concentrated in stablecoins and a handful of top-10 altcoins such as SOL, XRP, BNB, DOG, HYPE, and LINK. Smaller altcoins receive far less liquidity, making it hard for their prices to return to levels where investors previously bought. This creates a situation where only a few win while most face losses. Retail investors also tend to diversify across many coins instead of adding size to top altcoins. That explains why many portfolios remain stagnant despite a broader market rally. Sponsored “Position sizing is everything. Many people hold 25–30 tokens at once. A 100x on a token that makes up only 1% of your portfolio won’t meaningfully change your life. It’s better to make a few high-conviction bets than to overdiversify,” analyst The DeFi Investor said. Altcoin Index Surges but Investor Sentiment Remains Cautious The Altcoin Season Index from Blockchain Center now stands at 80 points. This indicates that over 80% of the top 50 altcoins outperformed…
Share
BitcoinEthereumNews2025/09/18 01:43