Markets Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail Solana Traders Hit by Months-Long Markets Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail Solana Traders Hit by Months-Long

Solana Traders Hit by Months-Long Browser Malware That Skimmed Every Swap

2025/11/28 13:03
5 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
Share
Share this article
Copy linkX (Twitter)LinkedInFacebookEmail

Solana Traders Hit by Months-Long Browser Malware That Skimmed Every Swap

Wallet interfaces typically summarize instructions as a single swap, and the bundled transaction executes atomically—meaning users unknowingly sign off on both.

By Shaurya Malwa|Edited by Omkar Godbole
Updated Nov 28, 2025, 5:32 a.m. Published Nov 28, 2025, 5:03 a.m.

What to know:

  • A Chrome extension called 'Crypto Copilot' secretly redirected fees from Solana trades to an attacker's wallet.
  • The extension, flagged by cybersecurity firm Socket, was available on the Chrome Web Store since June.
  • Users are advised to avoid closed-source extensions with signing privileges and move assets if they used Crypto Copilot.

A Chrome extension posing as a Solana trading assistant quietly siphoned fees from user swaps for months, using obfuscated transaction logic to route a slice of every trade to an attacker-controlled wallet.

Flagged by Cybersecurity firm Socket earlier this week, the ‘Crypto Copilot’ extension had been available on the Chrome Web Store since June as a convenience tool for traders on popular Solana DEX Raydium.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters
Sign me up

However, Socket found it injected a second instruction into every Raydium swap — transferring either 0.0013 SOL or 0.05% of the trade amount to a hardcoded wallet.

The exploit relied on a simple mechanism of generating the correct Raydium swap instruction, then appending a hidden transfer.

This worked because wallet interfaces typically summarize instructions as a single swap, and the bundled transaction executes atomically — meaning users unknowingly sign off on both. Imagine ordering a burger through a fast-food app where the "confirm order" button actually bundles payment, receipt printing, and handing over your food and change—all in one seamless move.

On-chain flows suggest limited adoption so far, with only small amounts collected by the attacker. But the mechanism scales with size: trades above roughly 2.6 SOL trigger the 0.05% fee, meaning a 100 SOL swap would siphon 0.05 SOL, or about $10 at current prices.

Several other signals point to a hastily assembled infrastructure. The extension’s primary domain, cryptocopilot[.]app, is parked on GoDaddy, while its backend — crypto-coplilot-dashboard[.]vercel[.]app, complete with a misspelling — returns a blank page despite collecting wallet metadata.

Socket said it has submitted a formal takedown request to Google, though the extension remained live at the time of writing. It warned users to avoid closed-source extensions that request signing privileges and to migrate assets to fresh wallets if they interacted with Crypto Copilot.

HackSolana News

More For You

Protocol Research: GoPlus Security

Commissioned byGoPlus

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
View Full Report

More For You

Why Gold Is Winning Over Bitcoin in 2025: Liquidity, Trade, and Trust

Despite ETF hype, central banks and asset allocators continue to choose gold over crypto for reserve and trade purposes.

What to know:

  • Gold has outperformed bitcoin since the launch of spot BTC ETFs, rising 58% as bitcoin fell 12%.
  • Mark Connors says bitcoin remains “too young” for institutional trust, while gold continues to benefit from established infrastructure and trade use.
  • Bitcoin’s recent slump reflects a global liquidity squeeze, not sentiment, with Connors pointing to U.S. Treasury spending delays as a key factor.
Read full story
Latest Crypto News

Strategy CEO: Equity and Debt Flexibility Power Long-Term Bitcoin Accumulation Plan

Crypto Payments Firm Truther to Launch Non-Custodial USDT Visa Card in El Salvador

State of Crypto: Kalshi and Prediction Markets Face a Setback

‘Privacy Is the Immune System of Freedom’: Crypto Advocacy Sparks Uproar in São Paulo


Why Gold Is Winning Over Bitcoin in 2025: Liquidity, Trade, and Trust

Bitcoin Pricing in 'Most Bearish Global Growth Outlook' Since Covid and FTX Crash: Bitwise Research

Top Stories

Bitcoin's 'Coinbase Premium' Flips Positive After Weeks in the Red

Why Gold Is Winning Over Bitcoin in 2025: Liquidity, Trade, and Trust

State of Crypto: Kalshi and Prediction Markets Face a Setback

‘Privacy Is the Immune System of Freedom’: Crypto Advocacy Sparks Uproar in São Paulo


Bitcoin Pricing in 'Most Bearish Global Growth Outlook' Since Covid and FTX Crash: Bitwise Research

Bitcoin in Modest Rally Mode After Thanksgiving as December Fed Rate Gets Locked In

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CME Group to launch Solana and XRP futures options in October

CME Group to launch Solana and XRP futures options in October

The post CME Group to launch Solana and XRP futures options in October appeared on BitcoinEthereumNews.com. CME Group is preparing to launch options on SOL and XRP futures next month, giving traders new ways to manage exposure to the two assets.  The contracts are set to go live on October 13, pending regulatory approval, and will come in both standard and micro sizes with expiries offered daily, monthly and quarterly. The new listings mark a major step for CME, which first brought bitcoin futures to market in 2017 and added ether contracts in 2021. Solana and XRP futures have quickly gained traction since their debut earlier this year. CME says more than 540,000 Solana contracts (worth about $22.3 billion), and 370,000 XRP contracts (worth $16.2 billion), have already been traded. Both products hit record trading activity and open interest in August. Market makers including Cumberland and FalconX plan to support the new contracts, arguing that institutional investors want hedging tools beyond bitcoin and ether. CME’s move also highlights the growing demand for regulated ways to access a broader set of digital assets. The launch, which still needs the green light from regulators, follows the end of XRP’s years-long legal fight with the US Securities and Exchange Commission. A federal court ruling in 2023 found that institutional sales of XRP violated securities laws, but programmatic exchange sales did not. The case officially closed in August 2025 after Ripple agreed to pay a $125 million fine, removing one of the biggest uncertainties hanging over the token. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/cme-group-solana-xrp-futures
Share
BitcoinEthereumNews2025/09/17 23:55
Gold Slips Toward $4,000 as Persistent Inflation Data Bolsters Higher Rate Expectations

Gold Slips Toward $4,000 as Persistent Inflation Data Bolsters Higher Rate Expectations

BitcoinWorld Gold Slips Toward $4,000 as Persistent Inflation Data Bolsters Higher Rate Expectations Gold prices edged lower in early trading, approaching the
Share
bitcoinworld2026/06/30 07:50
MARA deploys military veterans to patrol MRSM hostels in bullying crackdown

MARA deploys military veterans to patrol MRSM hostels in bullying crackdown

KUALA LUMPUR, June 30 — A total of 16 Malaysian Armed Forces (ATM) veterans will report for duty as full-time ward...
Share
Malaymail2026/06/30 08:47