Chrome Extension Crypto Copilot Steals Solana via Hidden Transfer Fees
These articles are AI-generated summaries. Please check the original sources for full details.
Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps
The ‘Crypto Copilot’ Chrome extension, published in May 2024, secretly adds an unauthorized Solana transfer to Raydium swap transactions, redirecting funds to an attacker-controlled wallet. As of November 26, 2025, the extension remains available with 12 installs despite the discovered malicious behavior.
Why This Matters
Current blockchain security models rely heavily on user awareness of transaction details; however, obfuscated code within browser extensions bypasses this safeguard. This attack demonstrates a significant vulnerability where seemingly legitimate tools can silently extract funds, highlighting a potential loss scale in the thousands of dollars given the extension’s ability to siphon 0.05% of each swap.
Key Insights
- Extension Published Date: May 7, 2024 (Socket Security report)
- Obfuscation Techniques: Minification and variable renaming are used to conceal malicious code within the extension.
- Trust Exploitation: The extension leverages legitimate services like DexScreener and Helius RPC to appear trustworthy.
Working Example
(No code provided in context)
Practical Applications
- Use Case: Malicious actors targeting crypto users via browser extensions to silently extract funds from transactions.
- Pitfall: Over-reliance on extension trustworthiness without inspecting transaction details before signing, leading to unnoticed fund theft.
References:
Continue reading
Next article
Dark LLMs Aid Petty Criminals, Underwhelm Technically
Related Content
Fake Chrome Extension 'Safery' Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Malicious Chrome extension 'Safery' exfiltrates Ethereum seed phrases via Sui blockchain microtransactions, still available as of November 2025.
Trust Wallet Chrome Extension Hack Results in $7 Million Crypto Loss
Trust Wallet suffered a security breach in its Chrome extension v2.68, resulting in approximately $7 million in cryptocurrency losses for users.
Trust Wallet Hack: $8.5M Drained via Shai-Hulud Supply Chain Attack
Trust Wallet suffered an $8.5 million loss after a malicious Chrome extension update, stemming from a supply chain attack leveraging exposed GitHub secrets.