Skip to content

Solana Traders Hit by Malware Extension

Malicious Chrome Extension Siphons SOL from Raydium Swaps

  • The Crypto Copilot extension secretly adds a hidden transfer to each Solana swap, siphoning fees to an attacker’s wallet.
  • Security firm Socket discovered the extension uses obfuscated code and a misspelled backend domain to conceal its activities.
  • The theft mechanism scales with trade size, taking at least 0.0013 SOL or up to 0.05% of the transaction amount.
  • Despite being live since June, the extension remains available on the Chrome Web Store without user warnings.
  • Socket has requested a takedown from Google’s security team but it is still accessible as of now.

Crypto Copilot has been exploiting users by injecting hidden fees into Solana swaps under the guise of a trading assistant tool, impacting unsuspecting users since last June without disclosure in its marketing materials or store listing.

The extension’s exploit grows with trade volume, extracting significant amounts over time, yet remains active on the Chrome Web Store despite detection efforts by security experts. (Source)

Share