A dangerous Chrome browser extension is quietly stealing money from cryptocurrency traders on the Solana network.A dangerous Chrome browser extension is quietly stealing money from cryptocurrency traders on the Solana network.

Malicious Chrome Extension Secretly Steals From Solana Traders

The malicious tool, called “Crypto Copilot,” tricks users into thinking they’re using a helpful trading app while secretly taking a cut from every transaction.

Security researchers at Socket published their findings on November 25, 2024. The extension has been active since June 18, 2024, making it one of the longest-running crypto scams on Google’s Chrome Web Store.

How the Scam Works

Crypto Copilot markets itself as a convenient trading tool that lets users buy and sell Solana tokens directly from their Twitter feeds. The extension promises “instant trading” without switching between different apps or websites.

But behind this helpful appearance lies a sophisticated theft mechanism. Every time a user makes a trade through the extension, it secretly adds an extra transaction that sends money to the attacker’s wallet.

The extension steals either 0.0013 SOL (minimum amount) or 0.05% of the trade amount, whichever is larger. For trades exceeding 2.6 SOL, the fee becomes 0.05% of the swap amount.

Source: SocketSecurity

The stolen funds go to a specific wallet address: Bjeida13AjgPaUEU9xrh1iQMwxZC7QDdvSfg73oxQff7. According to blockchain records, the attacker has only collected a small amount so far because the extension hasn’t attracted many users.

Advanced Hiding Techniques

What makes this scam particularly dangerous is how well it hides the theft. The extension uses Raydium, a legitimate Solana trading platform, to process the actual trades. This makes everything look normal to users.

The malicious code is hidden using advanced techniques like minification and variable renaming, making it nearly impossible for regular users to detect. When users approve a transaction, their wallet shows what appears to be a single trade. In reality, two transactions happen at the same time – the legitimate trade and the hidden theft.

Most Solana wallets show simplified transaction summaries instead of detailed breakdowns. This design choice, meant to make wallets easier to use, actually helps hide the scam from users.

The extension also connects to fake websites designed to look legitimate. The backend domain “crypto-coplilot-dashboard.vercel.app” loads only a blank page, and the main website “cryptocopilot.app” is parked by GoDaddy. These red flags should warn users that something isn’t right.

Part of a Growing Problem

Crypto Copilot isn’t the first malicious Chrome extension targeting cryptocurrency users. In August 2024, Jupiter, a major Solana trading platform, warned users about a dangerous extension called “Bull Checker” that was completely draining wallets rather than skimming small amounts. Separately, security researchers have found other fake wallets ranking high in Chrome Web Store search results.

In June 2024, a Chinese trader lost $1 million after installing a Chrome extension called “Aggr.” That extension stole browser cookies and hijacked accounts on centralized exchanges like Binance.

Recent research found 186 malicious cryptocurrency extensions out of 3,599 analyzed over 18 months. These fake tools have stolen over $1 million worth of cryptocurrency from unsuspecting users.

The problem is getting worse as more people use browser extensions for cryptocurrency trading. Chrome’s massive user base and flexible permission system make it an attractive target for scammers.

Why Solana Users Are Vulnerable

Solana’s technical design makes it easier for scammers to hide malicious transactions. The network allows multiple actions to happen in a single transaction, which attackers use to bundle legitimate trades with hidden thefts.

Many Solana users also trade meme coins and other fast-moving tokens, making them more likely to use tools that promise quick, convenient trading. This urgency can lead people to install extensions without carefully checking their legitimacy.

The extension specifically targets users following token discussions on Twitter, where crypto trading happens at a rapid pace. The promise of “one-click trading” appeals to traders who don’t want to miss opportunities while switching between different platforms.

How to Stay Safe

Security experts recommend several steps to protect against malicious extensions:

First, always review transaction details before approving them. Look for unexpected transfers or instructions that don’t match what you intended to do. On Solana, check for any SystemProgram.transfer instructions you didn’t expect.

Second, only install extensions from verified developers with good reputations. Avoid downloading extensions that request excessive permissions, especially the ability to read and modify all website data.

Third, if you’ve already installed Crypto Copilot, move your cryptocurrency to a new, clean wallet immediately. Also revoke all website connections for your old wallet to prevent further unauthorized access.

The extension was published by a user named “sjclark76” and currently has only 15-18 users with a one-star rating on the Chrome Web Store. Socket submitted a takedown request to Google, but the extension remained available as of late November 2024.

Users should also be skeptical of extensions that promise unrealistic convenience or profits. Legitimate trading tools typically require users to visit actual trading platforms rather than offering shortcuts through browser extensions.

The Bottom Line

The Crypto Copilot scam shows how cryptocurrency thieves are becoming more sophisticated. Instead of trying to steal entire wallets at once, they’re now using subtle, long-term strategies that are harder to detect.

This approach is particularly dangerous because victims might not notice small amounts being stolen over time. For active traders, these tiny thefts can add up to significant losses over weeks or months.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Share
BitcoinEthereumNews2025/09/18 00:14
Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Coinbase Joins Ethereum Foundation to Back Open Intents Framework

Coinbase Joins Ethereum Foundation to Back Open Intents Framework

Coinbase Payments has joined the Open Intents Framework as a core contributor, working alongside Ethereum Foundation and other major players. The initiative aims to simplify complex multi-chain interactions through automated solver technology. The post Coinbase Joins Ethereum Foundation to Back Open Intents Framework appeared first on Coinspeaker.
Share
Coinspeaker2025/09/18 02:43