TLDR A Chrome extension called “Crypto Copilot” has been stealing funds from Solana traders since June 2024 by secretly adding hidden transfer instructions to their trades. The malware skims either 0.0013 SOL or 0.05% from each swap on Raydium DEX, whichever amount is greater, sending it to an attacker’s wallet. The extension hides the theft [...] The post Malicious Chrome Extension Steals Solana Traders’ Funds Through Hidden Swap Fees appeared first on CoinCentral.TLDR A Chrome extension called “Crypto Copilot” has been stealing funds from Solana traders since June 2024 by secretly adding hidden transfer instructions to their trades. The malware skims either 0.0013 SOL or 0.05% from each swap on Raydium DEX, whichever amount is greater, sending it to an attacker’s wallet. The extension hides the theft [...] The post Malicious Chrome Extension Steals Solana Traders’ Funds Through Hidden Swap Fees appeared first on CoinCentral.

Malicious Chrome Extension Steals Solana Traders’ Funds Through Hidden Swap Fees

2025/11/28 16:51
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • A Chrome extension called “Crypto Copilot” has been stealing funds from Solana traders since June 2024 by secretly adding hidden transfer instructions to their trades.
  • The malware skims either 0.0013 SOL or 0.05% from each swap on Raydium DEX, whichever amount is greater, sending it to an attacker’s wallet.
  • The extension hides the theft using obfuscated code that bundles a legitimate swap with an invisible second instruction that wallet interfaces don’t clearly display to users.
  • Socket cybersecurity firm discovered the malware and submitted a takedown request to Google, but the extension remained available on the Chrome Web Store at time of reporting.
  • Users who installed Crypto Copilot are advised to move their assets to new wallets immediately, as the extension also sends wallet data to a suspicious backend server.

A Chrome extension marketed as a Solana trading tool has been quietly draining funds from users for five months. The extension, named Crypto Copilot, was discovered by cybersecurity firm Socket this week.

The malicious software has been available on the Chrome Web Store since June 2024. It presented itself as a convenience tool for traders using Raydium, a popular Solana decentralized exchange.

Socket’s research team found that the extension secretly modifies every transaction users make. When traders execute a swap on Raydium, the extension adds a hidden second instruction to the transaction.

This hidden instruction transfers funds to a wallet controlled by the attacker. The amount stolen is either 0.0013 SOL or 0.05% of the trade value, whichever is larger.

The theft mechanism works because wallet interfaces show users a simplified summary of transactions. When users approve what looks like a standard swap, they unknowingly sign off on two instructions bundled together.

The malicious code is heavily obfuscated through variable renaming and JavaScript minification. The attacker’s wallet address is buried deep inside the extension’s code under an innocuous variable name.

For trades larger than 2.6 SOL, the extension takes the full 0.05% cut. A 100 SOL swap would lose 0.05 SOL, worth approximately $10 at current prices.

Infrastructure and Backend Operations

Socket researchers discovered that Crypto Copilot connects to a backend server at crypto-coplilot-dashboard.vercel.app. The domain name contains a misspelling and displays only a blank page.

Despite the empty website, the extension regularly transmits data to this server. It sends connected wallet identifiers and user activity information.

The extension also uses a hardcoded Helius API key for transaction simulation and RPC calls. A separate domain, cryptocopilot.app, remains parked on GoDaddy.

Researchers noted the absence of documentation or functioning dashboard raises red flags. This infrastructure pattern matches other malicious browser extensions rather than legitimate trading products.

On-chain analysis shows limited funds collected so far in the attacker’s wallet. Investigators believe this reflects low user adoption rather than proof of safety.

Browser Extension Threats in 2025

The discovery comes as browser-based crypto attacks continue to rise. In July 2025, over 40 malicious Firefox extensions impersonated major wallet providers including MetaMask, Coinbase, Phantom, OKX, and Trust Wallet.

Those extensions stole wallet credentials directly from browsers and sent them to attacker servers. Major exchanges like OKX issued public warnings and filed complaints after discovering fake versions of their official tools.

Browser extensions have become one of the most common attack vectors this year. Wallet-related breaches accounted for $1.7 billion of the $2.2 billion stolen in the first half of 2025, according to CertiK data.

Phishing incidents added another $410 million to total losses. Despite the rise in extension attacks, overall crypto hacks briefly declined in October.

Current Status and User Warnings

Socket submitted a formal takedown request to Google for the Crypto Copilot extension. The extension remained available on the Chrome Web Store at the time of reporting.

Socket warns users to avoid closed-source extensions that request transaction signing privileges. Anyone who installed or used Crypto Copilot should move their assets to fresh wallets immediately.

PeckShield data shows October 2025 recorded just $18.18 million stolen across 15 incidents, the lowest monthly total of the year. The Crypto Copilot extension continues to operate as investigators work with Google on removal.

The post Malicious Chrome Extension Steals Solana Traders’ Funds Through Hidden Swap Fees appeared first on CoinCentral.

Market Opportunity
Solana Logo
Solana Price(SOL)
$91,77
$91,77$91,77
+2,03%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum price predictions are turning heads, with analysts suggesting ETH could climb to $10,000 by 2026 as institutional demand and network upgrades drive growth. While Ethereum remains a blue-chip asset, investors looking for sharper multiples are eyeing Layer Brett (LBRETT). Currently in presale at just $0.0058, the Ethereum Layer 2 meme coin is drawing huge [...] The post Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058 appeared first on Blockonomi.
Share
Blockonomi2025/09/17 23:45
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
Unleashing A New Era Of Seller Empowerment

Unleashing A New Era Of Seller Empowerment

The post Unleashing A New Era Of Seller Empowerment appeared on BitcoinEthereumNews.com. Amazon AI Agent: Unleashing A New Era Of Seller Empowerment Skip to content Home AI News Amazon AI Agent: Unleashing a New Era of Seller Empowerment Source: https://bitcoinworld.co.in/amazon-ai-seller-tools/
Share
BitcoinEthereumNews2025/09/18 00:10