MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Solana browser extension ‘Crypto Copilot’ caught secretly rerouting user funds into unauthorized trades
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$74,703.000.87%
  • ethereumEthereum(ETH)$2,340.900.70%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.413.89%
  • binancecoinBNB(BNB)$622.351.26%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.092.41%
  • tronTRON(TRX)$0.3257441.10%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.16%
  • dogecoinDogecoin(DOGE)$0.0959743.17%
Crypto NewsBlockchain

Solana browser extension ‘Crypto Copilot’ caught secretly rerouting user funds into unauthorized trades

rahulbadiyafad150c105
Last updated: November 28, 2025 1:27 pm
rahulbadiyafad150c105
Published: 5 months ago
Share

A Chrome browser extension designed for Solana trading has been exposed for secretly siphoning user funds by inserting hidden transfer instructions into swap transactions, according to a new report from cybersecurity firm Socket’s Threat Research Team.

The extension, called Crypto Copilot, allows users to trade SOL directly from X (formerly Twitter), but Socket found that it covertly redirects a portion of every trade to a wallet controlled by the attacker. Each swap includes a concealed instruction transferring 0.05% of the transaction value — or at least 0.0013 SOL — to a hardcoded address, the firm said.

Published on the Chrome Web Store in mid-2024, Crypto Copilot promotes itself as a fast Solana trading assistant. However, Socket noted that users see only a simplified swap summary during confirmation, with the malicious transfer omitted from the interface.

The extension hides its true behavior using obfuscation techniques such as code minification and variable renaming, according to the analysis. It also communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, which logs connected wallets, tracks user activity, and collects referral information. A second associated domain, cryptocopilot.app, remains inactive — a red flag for a legitimate trading service, Socket said.

Crypto Copilot routes swaps through Raydium, a popular Solana automated market maker. The malicious code attaches a hidden SystemProgram.transfer instruction to each Raydium trade, resulting in an on-chain atomic transaction that moves funds to the attacker while appearing to the user as a single normal swap.

Hidden siphoning poses compounding risk

Although the extension’s installation numbers appear limited, Socket warned that small, repeated deductions could result in significant losses for active traders. The incident underscores the growing risks associated with browser-based crypto tools, which have been targeted in past attacks involving malicious Chrome and Firefox extensions impersonating wallets such as MetaMask, Phantom, and Coinbase Wallet.

Socket said the case highlights persistent vulnerabilities in browser-based crypto trading and the need for stricter monitoring of the Chrome extension ecosystem. As more trading features migrate into browser add-ons, users face increased risks from hidden transaction manipulation.

The firm urged Solana users to verify the legitimacy of extensions, inspect all transaction data before approving a swap, and monitor ongoing security research for new threats.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Bitcoin leverage hits 5-year high – How ONE move could trigger pullback
Asian markets limp into weekend as AI bubble fears grow
The AI Trade: Opportunity Or Warning? – Conservative Angle
$ETH Climbs, $LINK Breaks Resistance – Top Cryptos to Join for Oct 2025 as $MOBU Presale Targets 9256% ROI
Top Meme Coins to Buy Before Ethereum Enters Price Discovery Mode: Why Traders Favor Pepe and Layer Brett – Crypto Economy
TAGGED:AltcoinBlockchainCrypto CopilotcryptocurrenciesextensionGoogleSolana

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Former Just Cause director will reveal his Max Payne-style game on Dec. 4
Next Article WEMADE Joins Forces with Chainalysis, CertiK and SentBe to Form Global Alliance for Korean Won Stablecoin
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d