Crypto Copilot Chrome Extension Steals Solana via Hidden Fees

Malicious Chrome Extension Crypto Copilot Steals Solana Tokens During Raydium Swaps with Hidden Fees

  • A Chrome extension named Crypto Copilot injects hidden Solana token (SOL) transfers during swaps, diverting funds to an attacker’s wallet.
  • The extension was published on the Chrome Web Store on May 7, 2024, and remains available with at least 12 installs.
  • It targets Raydium, a decentralized exchange on the Solana Blockchain, by modifying swap transactions with stealth fees.
  • The hidden fee ranges from a minimum of about $0.03 to 2.6 SOL (~$100) plus 0.05% of the swap amount, sent to a hardcoded wallet.
  • The extension uses code obfuscation and legitimate crypto services to avoid detection and appear trustworthy.

A malicious browser extension called Crypto Copilot has been found on the Chrome Web Store injecting unnoticed Solana (SOL) transfers into swap transactions. Discovered by Cybersecurity researchers, the extension diverts cryptocurrency to an attacker-controlled wallet during user trades. It was published on May 7, 2024, by a user named “sjclark76” and currently has 12 installs.

- Advertisement -

Crypto Copilot targets swaps made via Raydium, a decentralized exchange (DEX) and automated market maker on the Solana blockchain. The extension adds a hidden transfer using the SystemProgram.transfer method, which silently sends funds to a hardcoded wallet before the user signs the transaction. The fee is a minimum of 0.0013 SOL (approx. $0.03) or 0.05% of the swap amount, increasing to 2.6 SOL (~$100) plus 0.05% for larger trades.

The extension employs obfuscated and minified code to hide its activities and evade detection. Despite its malicious intent, Crypto Copilot interacts with legitimate services like DexScreener and Helius RPC to appear authentic. It also communicates with backend domains, including “crypto-coplilot-dashboard.vercel[.]app” and “cryptocopilot[.]app,” none of which host genuine products.

Socket security researcher Kush Pandya noted that users are unaware of these hidden fees as the user interface only displays standard swap details. As stated in the Socket report, the extension silently siphons a minimum of 0.0013 SOL or 0.05% from each swap to a personal wallet rather than a protocol treasury, making detection difficult without thorough transaction inspection.

Despite the risks, the extension remains available on the Chrome Web Store and continues to exploit users conducting Solana token swaps.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Aave CEO Urges RWA Push After Governance Vote Rejection Now.

Stani Kulechov outlined a wider strategy after a governance vote rejected a proposal to...

SEC Commissioner Caroline Crenshaw Resigns; Crypto Win Ahead

Caroline Crenshaw has resigned from the Securities and Exchange Commission, announced in a Friday...

CryptoQuant: Whale ‘Reaccumulation’ Narrative Overstated Now

Onchain data from CryptoQuant indicate claims of large-scale Bitcoin reaccumulation by whales are overstated.Exchange...

XRP Eyes Rally as ETFs and Buy Signal Boost 2026 Hopes Surge

Ripple settled its US lawsuit in 2025, helping XRP reach a $3.65 all-time high...

Bitfinex Hacker Ilya Lichtenstein Freed Early via First Step

Ilya Lichtenstein was released from prison after serving 14 months of a five-year sentence...
- Advertisement -

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Bitcoin (BTC) $ 89,899.00 1.40%
Ethereum (ETH) $ 3,123.09 4.05%
XRP (XRP) $ 2.01 7.16%
Bittensor (TAO) $ 248.84 8.41%
Polkadot (DOT) $ 2.15 7.46%
Cardano (ADA) $ 0.395202 10.81%
Chainlink (LINK) $ 13.30 5.51%
Hyperliquid (HYPE) $ 24.52 1.39%
Monero (XMR) $ 424.51 1.01%
Hedera (HBAR) $ 0.122037 6.90%
Toncoin (TON) $ 1.80 6.19%