TLDR Crypto Copilot stole SOL through hidden swap instructions in user wallets. Malicious extension rerouted tiny amounts per trade undetected for months. Experts warn high-volume Solana traders faced amplified hidden losses. Obfuscated code masked secret transfers, bypassing swap approval screens. Extension exposed—users urged to revoke access and move crypto immediately. A new report revealed that [...] The post Crypto Copilot Extension Exposed for Secretly Draining Solana Wallets appeared first on CoinCentral.TLDR Crypto Copilot stole SOL through hidden swap instructions in user wallets. Malicious extension rerouted tiny amounts per trade undetected for months. Experts warn high-volume Solana traders faced amplified hidden losses. Obfuscated code masked secret transfers, bypassing swap approval screens. Extension exposed—users urged to revoke access and move crypto immediately. A new report revealed that [...] The post Crypto Copilot Extension Exposed for Secretly Draining Solana Wallets appeared first on CoinCentral.

Crypto Copilot Extension Exposed for Secretly Draining Solana Wallets

2025/11/28 16:17
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • Crypto Copilot stole SOL through hidden swap instructions in user wallets.
  • Malicious extension rerouted tiny amounts per trade undetected for months.
  • Experts warn high-volume Solana traders faced amplified hidden losses.
  • Obfuscated code masked secret transfers, bypassing swap approval screens.
  • Extension exposed—users urged to revoke access and move crypto immediately.

A new report revealed that Crypto Copilot injected unauthorized transfer instructions into Solana swaps for months, silently diverting funds from wallets. The Chrome extension appeared legitimate but embedded malicious code that rerouted a portion of each transaction to an attacker-controlled address. Analysts confirmed that the behavior remained concealed during transaction approval, raising significant concerns over browser-based crypto tools.

Crypto Copilot Extension Exposed for Secretly Draining Solana Wallets

Crypto Copilot operated as a trading assistant, allowing users to execute swaps directly through browser wallets. It consistently inserted a second instruction into Raydium transactions, transferring either 0.0013 SOL or 0.05% of the trade value to a hardcoded wallet. Users unknowingly approved these actions because transaction summaries displayed only the main swap.

Investigators stated that Crypto Copilot collected public wallet data and interacted with servers, although the backend displayed no functional dashboard. The extension used obfuscated JavaScript to conceal the malicious process, making detection difficult through standard inspection. In addition, the primary associated domain remained parked, which suggested limited or incomplete backend infrastructure.

Cybersecurity experts linked Crypto Copilot to a wider pattern of browser extension attacks targeting wallet transactions. They emphasized that incremental fund siphoning accumulated over time, particularly in large-volume swaps. Consequently, frequent Solana traders faced greater risk due to repetitive exposure.

Solana-Based Swaps Manipulated Through Atomic Transactions

The extension used Raydium protocols to build legitimate swap instructions and then appended the hidden transfer. Each confirmed transaction executed atomically, which granted Crypto Copilot the ability to siphon funds without separate approval. As a result, users unknowingly signed transactions that bundled both swap execution and token transfer.

On-chain data suggested limited adoption; however, the exploit scaled in proportion to trade size. For example, a 100 SOL swap resulted in a diversion of 0.05 SOL. High-volume activity amplified potential losses despite low installation numbers.

Crypto Copilot integrated smoothly with popular wallet interfaces, further masking its hidden transfer feature. The interface appeared safe, but users could not easily view underlying instructions. Collected wallet metadata flowed to attacker-operated servers, further heightening security concerns.

Browser-Based Crypto Tools Under Scrutiny

The exposure of Crypto Copilot raised concerns over security practices within the Chrome extension ecosystem. Experts recommended reviewing installed extensions, moving assets to hardware wallets, and inspecting blockchain transactions before authorization. They also advised immediate fund migration to new wallets for users who interacted with the extension.

Past incidents involved malicious extensions targeting tools such as Phantom, MetaMask, and Coinbase wallets. Crypto Copilot demonstrated how small, concealed instructions can escape user scrutiny during transaction approval. Industry specialists called for enhanced monitoring of browser-based trading tools as decentralized finance adoption increases.

The post Crypto Copilot Extension Exposed for Secretly Draining Solana Wallets appeared first on CoinCentral.

Market Opportunity
Solana Logo
Solana Price(SOL)
$91.65
$91.65$91.65
+1.90%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Rising geopolitical tension often exposes the hidden cracks in global finance, and few regions demonstrate this more clearly than the Strait of Hormuz. As a critical
Share
Timestabloid2026/03/24 04:05
US Dollar and Oil fall as Trump signals Iran de-escalation

US Dollar and Oil fall as Trump signals Iran de-escalation

The post US Dollar and Oil fall as Trump signals Iran de-escalation appeared on BitcoinEthereumNews.com. Here is what you need to know for Tuesday, March 24: The
Share
BitcoinEthereumNews2026/03/24 04:06
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45