BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Crypto Copilot Chrome Extension Steals Solana via Hidden Fees

Malicious Chrome Extension Crypto Copilot Steals Solana Tokens During Raydium Swaps with Hidden Fees

  • A Chrome extension named Crypto Copilot injects hidden Solana token (SOL) transfers during swaps, diverting funds to an attacker’s wallet.
  • The extension was published on the Chrome Web Store on May 7, 2024, and remains available with at least 12 installs.
  • It targets Raydium, a decentralized exchange on the Solana Blockchain, by modifying swap transactions with stealth fees.
  • The hidden fee ranges from a minimum of about $0.03 to 2.6 SOL (~$100) plus 0.05% of the swap amount, sent to a hardcoded wallet.
  • The extension uses code obfuscation and legitimate crypto services to avoid detection and appear trustworthy.

A malicious browser extension called Crypto Copilot has been found on the Chrome Web Store injecting unnoticed Solana (SOL) transfers into swap transactions. Discovered by Cybersecurity researchers, the extension diverts cryptocurrency to an attacker-controlled wallet during user trades. It was published on May 7, 2024, by a user named “sjclark76” and currently has 12 installs.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Crypto Copilot targets swaps made via Raydium, a decentralized exchange (DEX) and automated market maker on the Solana blockchain. The extension adds a hidden transfer using the SystemProgram.transfer method, which silently sends funds to a hardcoded wallet before the user signs the transaction. The fee is a minimum of 0.0013 SOL (approx. $0.03) or 0.05% of the swap amount, increasing to 2.6 SOL (~$100) plus 0.05% for larger trades.

The extension employs obfuscated and minified code to hide its activities and evade detection. Despite its malicious intent, Crypto Copilot interacts with legitimate services like DexScreener and Helius RPC to appear authentic. It also communicates with backend domains, including “crypto-coplilot-dashboard.vercel[.]app” and “cryptocopilot[.]app,” none of which host genuine products.

Socket security researcher Kush Pandya noted that users are unaware of these hidden fees as the user interface only displays standard swap details. As stated in the Socket report, the extension silently siphons a minimum of 0.0013 SOL or 0.05% from each swap to a personal wallet rather than a protocol treasury, making detection difficult without thorough transaction inspection.

Despite the risks, the extension remains available on the Chrome Web Store and continues to exploit users conducting Solana token swaps.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Write a 60 character news title related to Google stock is strong buy – that’s the consensus right now among all 44 analysts covering...

All 44 analysts covering Alphabet's stock maintain a "Strong Buy" consensus, with zero Sell...

Fed Decision Tests Bitcoin ETF’s $1.16B Weekly Inflow Streak

Spot Bitcoin ETFs have recorded seven straight days of inflows, totaling $1.16 billion, according...

BlackRock’s Crypto Yield Sparks Ethereum Surge to $2,300

Ethereum’s price and open interest have surged together, signaling potential for a major price...

UK parliamentary committee seeks crypto donation moratorium

A UK cross-party committee urges an immediate moratorium on crypto donations to political parties.The...

Apple Patches WebKit Zero-Day in iOS, macOS

Apple released its first Background Security Improvements to patch a cross-origin vulnerability in WebKit.The...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading