MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Chrome Extension Secretly Steals from Solana Traders
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$66,969.001.52%
  • ethereumEthereum(ETH)$2,025.351.98%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$616.831.24%
  • rippleXRP(XRP)$1.351.40%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$83.730.61%
  • tronTRON(TRX)$0.3151132.00%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.75%
  • dogecoinDogecoin(DOGE)$0.0940594.22%
NFTs

Chrome Extension Secretly Steals from Solana Traders

Last updated: November 28, 2025 2:00 am
Published: 4 months ago
Share

Hassan, a Cryptonews.com journalist with 6+ years of experience in Web3 journalism, brings deep knowledge across Crypto, Web3 Gaming, NFTs, and Play-to-Earn sectors. His work has appeared in…

A newly discovered malicious Chrome extension is stealing funds from Solana traders by quietly siphoning a fee from every swap they execute, according to new findings from Socket’s Threat Research Team.

The extension, called Crypto Copilot, has been available on the Chrome Web Store since June 2024 and markets itself as a shortcut for executing Solana trades directly from users’ X feeds.

Behind the interface, however, researchers found code designed to insert an additional transfer into each Raydium swap, diverting at least 0.0013 SOL, or 0.05% of each transaction, to an attacker-controlled wallet.

Crypto Copilot Sends Wallet Data to Suspicious Backend While Draining Trader Funds

Socket researchers say the extension constructs a normal Raydium swap instruction but then appends a second instruction that transfers SOL to the wallet address Bjeida.

Users only see the legitimate swap in the interface, and most wallet confirmation windows display only a high-level summary of the transaction rather than the full list of instructions.

As a result, traders approve what appears to be a standard transaction, unaware of the hidden transfer embedded inside it.

The fee logic is fully hardcoded inside the extension and buried under layers of obfuscated JavaScript.

Socket notes that the extension applies whichever is greater between the minimum fee and the percentage-based fee, meaning trades above 2.6 SOL incur the full 0.05% extraction.

Researchers found that the extension uses variable renaming and aggressive minification to conceal the behavior, and the attacker’s wallet is labeled under an innocuous variable deep inside the bundle.

The extension remains online at the time of reporting. Socket says it has submitted a takedown request to Google, but has not received confirmation that action has been taken.

Beyond the fee theft, investigators also discovered that Crypto Copilot connects to a backend hosted on crypto-coplilot-dashboard.vercel.app, a misspelled domain that shows only a blank placeholder page.

Despite the empty site, the extension regularly sends connected wallet identifiers and activity data to this backend, along with using a hardcoded Helius API key for transaction simulation and RPC calls.

A separate domain tied to the tool, cryptocopilot.app, is currently parked.

Researchers say the absence of documentation, a functioning dashboard, or any supporting infrastructure is inconsistent with a legitimate trading product and instead reflects common practices seen in malicious browser extensions.

While on-chain activity linked to the attacker’s wallet remains limited, investigators believe the low transaction volume likely reflects the extension’s relatively small distribution rather than an absence of risk.

They warn that the mechanism scales with trading activity, meaning high-volume users could lose larger amounts over time without noticing the incremental drain.

Crypto Losses Fall to 2025 Lows, but Browser Extension Attacks Continue to Climb

The discovery comes during a period of heightened scrutiny around browser-based crypto threats. In July, more than 40 malicious Firefox extensions were found impersonating major wallet providers, including MetaMask, Coinbase, Phantom, OKX, and Trust Wallet.

Those extensions harvested wallet credentials directly from users’ browsers and transmitted them to attacker-controlled servers.

Exchanges such as OKX publicly warned users and filed complaints after discovering fake plugins masquerading as official wallet tools. Browser extensions have emerged as one of the most persistent attack vectors in 2025, contributing to a growing share of crypto losses.

Wallet-related breaches accounted for $1.7 billion of the $2.2 billion stolen across the first half of the year, according to CertiK. Phishing incidents added another $410 million.

Despite the rise in extension-based threats, the broader crypto sector briefly experienced a decline in successful hacks.

PeckShield recorded just $18.18 million stolen across 15 incidents in October, the lowest monthly total of the year.

That figure had been far higher a month earlier when losses reached $127.06 million in September, driven by nearly 20 major exploits. But even as overall losses dipped, high-profile breaches continued.

Read more on cryptonews.com

This news is powered by cryptonews.com cryptonews.com

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

BexBack Celebrates 500,000 Traders With New Deposit Bonuses and $50 Welcome Reward
From Viral Prank to Unexpected Triumph: A Show’s Journey of Self-Discovery
Little Pepe Crypto Price Prediction: LILPEPE Shows Why It Ranks Among Best Meme Coins to Invest in Today
Crypto Regulation: US Senate Banking Updated Market Structure Bill
Logan Paul’s ‘holy grail’ of Pokémon cards sells for $16.5 million, with a diamond necklace thrown in

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Khabib’s $4.4M NFT sale sparks feud as McGregor slams ‘crypto scam’
Next Article These Platforms Work Best For Crypto Asset Management
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d