The post ‘Crypto Copilot’ Extension Sends SOL to Hacker: Details appeared on BitcoinEthereumNews.com. According to a recent report, the “Crypto Copilot” Chrome extension is siphoning SOL from anyone who installs it. The extension pretends to be a trading helper for Solana users, letting you execute swaps directly from X (Twitter) posts.  On the surface, it looks totally normal: it connects to standard wallets, shows DexScreener price data, and routes swaps through Raydium, Solana’s biggest AMM. But underneath that UI, it secretly injects an extra instruction into every transaction you sign. How it works  The extension quietly attaches a second instruction behind the scenes: a tiny, hidden SOL transfer to the attacker’s personal wallet. You never see it in the UI. Wallets like Phantom only show a summary unless you manually expand the instruction list. So most users never notice an outbound transfer buried inside the same transaction. The fee-extraction code itself is simple: it calculates either a tiny fixed fee or a tiny percentage of the trade, converts it to lamports, and then quietly adds a second instruction to the transaction that sends that amount to the attacker’s wallet.  What makes it dangerous is that this logic is buried inside heavily obfuscated JavaScript. On the surface, the UI looks completely legitimate, showing only the expected Raydium swap.  The extension also connects to a backend domain with a typo, which records wallet IDs, tracks activity, and pretends to provide “points” and referrals even though the actual website is empty and non-functional.  On-chain, the theft looks like tiny, ordinary SOL transfers sitting next to legitimate swaps. Hence, unless someone inspects instructions carefully or knows the attacker’s address, it blends in.. The fee is intentionally small enough to be ignored in the moment. Source: https://u.today/crypto-copilot-extension-sends-sol-to-hacker-detailsThe post ‘Crypto Copilot’ Extension Sends SOL to Hacker: Details appeared on BitcoinEthereumNews.com. According to a recent report, the “Crypto Copilot” Chrome extension is siphoning SOL from anyone who installs it. The extension pretends to be a trading helper for Solana users, letting you execute swaps directly from X (Twitter) posts.  On the surface, it looks totally normal: it connects to standard wallets, shows DexScreener price data, and routes swaps through Raydium, Solana’s biggest AMM. But underneath that UI, it secretly injects an extra instruction into every transaction you sign. How it works  The extension quietly attaches a second instruction behind the scenes: a tiny, hidden SOL transfer to the attacker’s personal wallet. You never see it in the UI. Wallets like Phantom only show a summary unless you manually expand the instruction list. So most users never notice an outbound transfer buried inside the same transaction. The fee-extraction code itself is simple: it calculates either a tiny fixed fee or a tiny percentage of the trade, converts it to lamports, and then quietly adds a second instruction to the transaction that sends that amount to the attacker’s wallet.  What makes it dangerous is that this logic is buried inside heavily obfuscated JavaScript. On the surface, the UI looks completely legitimate, showing only the expected Raydium swap.  The extension also connects to a backend domain with a typo, which records wallet IDs, tracks activity, and pretends to provide “points” and referrals even though the actual website is empty and non-functional.  On-chain, the theft looks like tiny, ordinary SOL transfers sitting next to legitimate swaps. Hence, unless someone inspects instructions carefully or knows the attacker’s address, it blends in.. The fee is intentionally small enough to be ignored in the moment. Source: https://u.today/crypto-copilot-extension-sends-sol-to-hacker-details

‘Crypto Copilot’ Extension Sends SOL to Hacker: Details

For feedback or concerns regarding this content, please contact us at [email protected]

According to a recent report, the “Crypto Copilot” Chrome extension is siphoning SOL from anyone who installs it.

The extension pretends to be a trading helper for Solana users, letting you execute swaps directly from X (Twitter) posts. 

On the surface, it looks totally normal: it connects to standard wallets, shows DexScreener price data, and routes swaps through Raydium, Solana’s biggest AMM.

But underneath that UI, it secretly injects an extra instruction into every transaction you sign.

How it works 

The extension quietly attaches a second instruction behind the scenes: a tiny, hidden SOL transfer to the attacker’s personal wallet.

You never see it in the UI. Wallets like Phantom only show a summary unless you manually expand the instruction list. So most users never notice an outbound transfer buried inside the same transaction.

The fee-extraction code itself is simple: it calculates either a tiny fixed fee or a tiny percentage of the trade, converts it to lamports, and then quietly adds a second instruction to the transaction that sends that amount to the attacker’s wallet. 

What makes it dangerous is that this logic is buried inside heavily obfuscated JavaScript. On the surface, the UI looks completely legitimate, showing only the expected Raydium swap. 

The extension also connects to a backend domain with a typo, which records wallet IDs, tracks activity, and pretends to provide “points” and referrals even though the actual website is empty and non-functional. 

On-chain, the theft looks like tiny, ordinary SOL transfers sitting next to legitimate swaps. Hence, unless someone inspects instructions carefully or knows the attacker’s address, it blends in.. The fee is intentionally small enough to be ignored in the moment.

Source: https://u.today/crypto-copilot-extension-sends-sol-to-hacker-details

Market Opportunity
Solana Logo
Solana Price(SOL)
$86.99
$86.99$86.99
-0.68%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CryptoQuant: Unrealized profits of whales holding 10,000 to 100,000 ETH hit a new high in November 2021

CryptoQuant: Unrealized profits of whales holding 10,000 to 100,000 ETH hit a new high in November 2021

PANews reported on September 18th that CryptoQuant analyst CryptoOnchain reported that the unrealized profits of medium-sized whales holding 10,000 to 100,000 ETH in Ethereum wallets have climbed to levels last seen in November 2021, when ETH hit its all-time high. This suggests these whales are currently holding significant paper gains, similar to the situation at the previous market peak. Historical data shows that such high levels of unrealized profits are often accompanied by increased selling pressure or profit-taking, potentially influencing price trends. While this may not necessarily trigger an immediate market correction, investor psychology and whale behavior at this stage could have a significant impact on price fluctuations.
Share
PANews2025/09/18 15:37
Coinbase Joins Ethereum Foundation to Back Open Intents Framework

Coinbase Joins Ethereum Foundation to Back Open Intents Framework

Coinbase Payments has joined the Open Intents Framework as a core contributor, working alongside Ethereum Foundation and other major players. The initiative aims to simplify complex multi-chain interactions through automated solver technology. The post Coinbase Joins Ethereum Foundation to Back Open Intents Framework appeared first on Coinspeaker.
Share
Coinspeaker2025/09/18 02:43
How will this Middle East war reshape your assets in 12 months?

How will this Middle East war reshape your assets in 12 months?

Original post: @radigancarter Compiled by: Big Claws | PANew Lobster I've been thinking about this issue on and off for about a week, while also dealing with the
Share
PANews2026/03/23 12:12