The post Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades appeared on BitcoinEthereumNews.com. Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks. Summary Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​ Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​ Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification. A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team. The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address. Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated. The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said. A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms. Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users… The post Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades appeared on BitcoinEthereumNews.com. Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks. Summary Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​ Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​ Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification. A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team. The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address. Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated. The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said. A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms. Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users…

Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

For feedback or concerns regarding this content, please contact us at [email protected]

Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks.

Summary

  • Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​
  • Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​
  • Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification.

A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team.

The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address.

Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated.

The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said.

A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms.

Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users approve what appears to be a single transaction, according to the report.

Solana browser extension Crypto Copilot studied by Socket

Although installation numbers remain low, Socket warned that cumulative losses pose significant risks for frequent traders. Incremental fund diversions may accumulate undetected, illustrating broader security threats posed by browser-based cryptocurrency tools, the firm stated.

Previous incidents have involved malicious Chrome and Firefox extensions targeting cryptocurrency wallets including MetaMask, Phantom, and Coinbase, according to industry reports.

The incident highlights vulnerabilities in browser-based cryptocurrency security and the importance of transaction verification before approval, Socket stated. As browser-based tools increasingly integrate cryptocurrency trading functionality, enhanced monitoring and oversight of Chrome’s extension ecosystem may be necessary to protect decentralized finance users, the report concluded.

Solana traders are advised to verify extension legitimacy, review transaction instructions in detail, and monitor updates from cybersecurity researchers, according to Socket.

Source: https://crypto.news/solana-browser-extension-crypto-copilot-exposed-for-diverting-user-funds-in-secret-trades/

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00999
$0.00999$0.00999
0.00%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Rising geopolitical tension often exposes the hidden cracks in global finance, and few regions demonstrate this more clearly than the Strait of Hormuz. As a critical
Share
Timestabloid2026/03/24 04:05
US Dollar and Oil fall as Trump signals Iran de-escalation

US Dollar and Oil fall as Trump signals Iran de-escalation

The post US Dollar and Oil fall as Trump signals Iran de-escalation appeared on BitcoinEthereumNews.com. Here is what you need to know for Tuesday, March 24: The
Share
BitcoinEthereumNews2026/03/24 04:06
Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales offload 200 million XRP leaving market uncertainty behind. XRP faces potential collapse as whales drive major price shifts. Is XRP’s future in danger after massive sell-off by whales? XRP’s price has been under intense pressure recently as whales reportedly offloaded a staggering 200 million XRP over the past two weeks. This massive sell-off has raised alarms across the cryptocurrency community, as many wonder if the market is on the brink of collapse or just undergoing a temporary correction. According to crypto analyst Ali (@ali_charts), this surge in whale activity correlates directly with the price fluctuations seen in the past few weeks. XRP experienced a sharp spike in late July and early August, but the price quickly reversed as whales began to sell their holdings in large quantities. The increased volume during this period highlights the intensity of the sell-off, leaving many traders to question the future of XRP’s value. Whales have offloaded around 200 million $XRP in the last two weeks! pic.twitter.com/MiSQPpDwZM — Ali (@ali_charts) September 17, 2025 Also Read: Shiba Inu’s Price Is at a Tipping Point: Will It Break or Crash Soon? Can XRP Recover or Is a Bigger Decline Ahead? As the market absorbs the effects of the whale offload, technical indicators suggest that XRP may be facing a period of consolidation. The Relative Strength Index (RSI), currently sitting at 53.05, signals a neutral market stance, indicating that XRP could move in either direction. This leaves traders uncertain whether the XRP will break above its current resistance levels or continue to fall as more whales sell off their holdings. Source: Tradingview Additionally, the Bollinger Bands, suggest that XRP is nearing the upper limits of its range. This often points to a potential slowdown or pullback in price, further raising concerns about the future direction of the XRP. With the price currently around $3.02, many are questioning whether XRP can regain its footing or if it will continue to decline. The Aftermath of Whale Activity: Is XRP’s Future in Danger? Despite the large sell-off, XRP is not yet showing signs of total collapse. However, the market remains fragile, and the price is likely to remain volatile in the coming days. With whales continuing to influence price movements, many investors are watching closely to see if this trend will reverse or intensify. The coming weeks will be critical for determining whether XRP can stabilize or face further declines. The combination of whale offloading and technical indicators suggest that XRP’s price is at a crossroads. Traders and investors alike are waiting for clear signals to determine if the XRP will bounce back or continue its downward trajectory. Also Read: Metaplanet’s Bold Move: $15M U.S. Subsidiary to Supercharge Bitcoin Strategy The post Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse? appeared first on 36Crypto.
Share
Coinstats2025/09/17 23:42