Close Menu
Chain Tech Daily

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Major Bitcoin and Ethereum options expiry hits as open interest clusters near max pain

    November 28, 2025

    CZ’s net worth has risen $54 million per day since prison release

    November 28, 2025

    Allocation Update: Q1 2023 | Ethereum Foundation Blog

    November 28, 2025
    Facebook X (Twitter) Instagram
    Chain Tech Daily
    • Altcoins
      • Litecoin
      • Coinbase
      • Crypto
      • Blockchain
    • Bitcoin
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Chain Tech Daily
    Home » Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades
    Crypto

    Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

    James WilsonBy James WilsonNovember 28, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks.

    Summary

    • Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​
    • Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​
    • Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification.

    A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team.

    The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address.

    Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated.

    The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said.

    A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms.

    Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users approve what appears to be a single transaction, according to the report.

    Solana browser extension Crypto Copilot studied by Socket

    Although installation numbers remain low, Socket warned that cumulative losses pose significant risks for frequent traders. Incremental fund diversions may accumulate undetected, illustrating broader security threats posed by browser-based cryptocurrency tools, the firm stated.

    Previous incidents have involved malicious Chrome and Firefox extensions targeting cryptocurrency wallets including MetaMask, Phantom, and Coinbase, according to industry reports.

    The incident highlights vulnerabilities in browser-based cryptocurrency security and the importance of transaction verification before approval, Socket stated. As browser-based tools increasingly integrate cryptocurrency trading functionality, enhanced monitoring and oversight of Chrome’s extension ecosystem may be necessary to protect decentralized finance users, the report concluded.

    Solana traders are advised to verify extension legitimacy, review transaction instructions in detail, and monitor updates from cybersecurity researchers, according to Socket.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    James Wilson

    Related Posts

    Crypto November 28, 2025

    Major Bitcoin and Ethereum options expiry hits as open interest clusters near max pain

    Crypto November 28, 2025

    Hyperliquid price nears breakdown ahead of $351M unlock

    Crypto November 28, 2025

    Balancer to repay liquidity providers $8M after v2 exploit

    Crypto November 28, 2025

    Swiss ETP launches meme coin

    Crypto November 28, 2025

    Bitcoin bounces back, but institutional selling lingers

    Crypto November 27, 2025

    $60 billion market predicted by 2026

    Leave A Reply Cancel Reply

    Don't Miss
    Crypto November 28, 2025

    Major Bitcoin and Ethereum options expiry hits as open interest clusters near max pain

    Large Bitcoin and Ethereum options expiry follows a major leverage washout, with open interest clustering…

    CZ’s net worth has risen $54 million per day since prison release

    November 28, 2025

    Allocation Update: Q1 2023 | Ethereum Foundation Blog

    November 28, 2025

    Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

    November 28, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • YouTube
    • LinkedIn
    Our Picks

    Major Bitcoin and Ethereum options expiry hits as open interest clusters near max pain

    November 28, 2025

    CZ’s net worth has risen $54 million per day since prison release

    November 28, 2025

    Allocation Update: Q1 2023 | Ethereum Foundation Blog

    November 28, 2025

    Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

    November 28, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Don't Miss
    Crypto November 28, 2025

    Major Bitcoin and Ethereum options expiry hits as open interest clusters near max pain

    Large Bitcoin and Ethereum options expiry follows a major leverage washout, with open interest clustering…

    CZ’s net worth has risen $54 million per day since prison release

    November 28, 2025

    Allocation Update: Q1 2023 | Ethereum Foundation Blog

    November 28, 2025

    Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

    November 28, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    About Us
    About Us

    ChainTechDaily.xyz delivers the latest updates and trends in the world of cryptocurrency. Stay informed with daily news, insights, and analysis tailored for crypto enthusiasts.

    Our Picks
    Lithosphere News Releases

    FurGPT Accelerates Listing Momentum with Exchange Partnerships and Ecosystem Growth

    November 18, 2025

    AI Pets Platform FurGPT Prepares to List FGPT Token on Binance Exchange and Aster DEX

    November 18, 2025

    Imagen Network Collaborates with xAI to Unlock Multimodal Creation in Web3 Ecosystems

    November 18, 2025

    FurGPT Invests in Kadena Chainweb EVM to Advance Decentralized AI Infrastructure

    November 18, 2025
    X (Twitter) Instagram YouTube LinkedIn
    © 2025 Copyright

    Type above and press Enter to search. Press Esc to cancel.