Malicious Chrome Extension Exploits Solana Swaps, Stealing User Funds A recently identified malicious Google Chrome extension is facilitating fake Solana trades while covertly siphoning a portion of each transaction into the attacker’s wallet. The extension, dubbed Crypto Copilot, manipulates users attempting to execute swaps on the Solana blockchain, according to a report from cybersecurity firm [...]Malicious Chrome Extension Exploits Solana Swaps, Stealing User Funds A recently identified malicious Google Chrome extension is facilitating fake Solana trades while covertly siphoning a portion of each transaction into the attacker’s wallet. The extension, dubbed Crypto Copilot, manipulates users attempting to execute swaps on the Solana blockchain, according to a report from cybersecurity firm [...]

Malicious Chrome Extension Steals SOL Crypto Without Draining Wallets

Malicious Chrome Extension Steals Sol Crypto Without Draining Wallets

Malicious Chrome Extension Exploits Solana Swaps, Stealing User Funds

A recently identified malicious Google Chrome extension is facilitating fake Solana trades while covertly siphoning a portion of each transaction into the attacker’s wallet. The extension, dubbed Crypto Copilot, manipulates users attempting to execute swaps on the Solana blockchain, according to a report from cybersecurity firm Socket.

Crypto Copilot allows users to trade Solana directly from their Twitter feeds, promising quick execution without switching apps. However, behind the scenes, the extension injects an additional transfer instruction into every swap—effectively draining a minimum of 0.0013 SOL or 0.05% of the total trade—without the user’s awareness. The mechanism leverages the decentralized exchange Raydium to facilitate these swaps, then appends a second, hidden transfer that reroutes SOL from the user’s wallet to the attacker’s address.

On the user interface, only the intended swap appears, with wallet confirmation screens summarizing the transaction without highlighting the extra, malicious instruction. “Users sign what appears to be a single swap, but both instructions execute atomically on-chain,” Socket explained.

Featured image of the Google Chrome extension. Source: Chrome Web Store

Socket has already submitted a takedown request to the Chrome Web Store security team. Despite being publicly available since June 18, 2024, the extension remains relatively obscure, with only 15 users reported so far. Crypto Copilot markets itself as an effortless way for Solana traders to execute swaps directly from social media, claiming to streamline trading opportunities without the hassle of multiple platform switches.

The proliferation of malicious Chrome extensions targeting the crypto community is well-documented. Earlier this month, Socket flagged another malicious wallet extension that drained user funds from the Chrome Web Store’s crypto ecosystem. In August, Jupiter, a decentralized exchange aggregator, identified yet another extension designed to empty Solana wallets. The risks are compounded by high-profile incidents, including a June 2024 case where a Chinese trader lost over $1 million after installing a rogue Binance plugin that hijacked account cookies.

As the browser extension ecosystem continues to attract malicious actors, security experts urge users to exercise caution when installing and confirming transactions in browser-based crypto tools. The ongoing exploitation highlights the importance of verifying extensions and transaction details before signing any blockchain-related activity.

This article was originally published as Malicious Chrome Extension Steals SOL Crypto Without Draining Wallets on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
Solana Logo
Solana Price(SOL)
$144.69
$144.69$144.69
+0.84%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

The post Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now? appeared on BitcoinEthereumNews.com. On the lookout for a Sector – Tech fund? Starting with Putnam Global Technology A (PGTAX – Free Report) should not be a possibility at this time. PGTAX possesses a Zacks Mutual Fund Rank of 4 (Sell), which is based on various forecasting factors like size, cost, and past performance. Objective We note that PGTAX is a Sector – Tech option, and this area is loaded with many options. Found in a wide number of industries such as semiconductors, software, internet, and networking, tech companies are everywhere. Thus, Sector – Tech mutual funds that invest in technology let investors own a stake in a notoriously volatile sector, but with a much more diversified approach. History of fund/manager Putnam Funds is based in Canton, MA, and is the manager of PGTAX. The Putnam Global Technology A made its debut in January of 2009 and PGTAX has managed to accumulate roughly $650.01 million in assets, as of the most recently available information. The fund is currently managed by Di Yao who has been in charge of the fund since December of 2012. Performance Obviously, what investors are looking for in these funds is strong performance relative to their peers. PGTAX has a 5-year annualized total return of 14.46%, and is in the middle third among its category peers. But if you are looking for a shorter time frame, it is also worth looking at its 3-year annualized total return of 27.02%, which places it in the middle third during this time-frame. It is important to note that the product’s returns may not reflect all its expenses. Any fees not reflected would lower the returns. Total returns do not reflect the fund’s [%] sale charge. If sales charges were included, total returns would have been lower. When looking at a fund’s performance, it…
Share
BitcoinEthereumNews2025/09/18 04:05
The whale "pension-usdt.eth" has reduced its ETH long positions by 10,000 coins, and its futures account has made a profit of $4.18 million in the past day.

The whale "pension-usdt.eth" has reduced its ETH long positions by 10,000 coins, and its futures account has made a profit of $4.18 million in the past day.

PANews reported on January 14th that, according to Hyperbot data monitoring, the whale "pension-usdt.eth" reduced its ETH long positions by 10,000 ETH in the past
Share
PANews2026/01/14 13:45
Senator Warren Tells OCC to Stop World Liberty Bank Review Amid Trump Ties

Senator Warren Tells OCC to Stop World Liberty Bank Review Amid Trump Ties

The post Senator Warren Tells OCC to Stop World Liberty Bank Review Amid Trump Ties appeared on BitcoinEthereumNews.com. U.S. Senator Elizabeth Warren has called
Share
BitcoinEthereumNews2026/01/14 12:55