The post Chrome Extension Exposed for Injecting Hidden SOL Fees appeared on BitcoinEthereumNews.com. The Hack: A Chrome extension named “Crypto Copilot” secretly adds a fee transfer to user swaps. The Trick: It hides a SystemProgram.transfer instruction inside legitimate Raydium transactions. The Fix: Users must verify individual transaction instructions in their wallet preview before signing. A malicious browser extension masquerading as a Solana trading tool has been caught siphoning funds from users by silently modifying transaction payloads. Security researchers identified the harmful Chrome extension to secretly steal small amounts of SOL from Solana users during swaps. The extension, named Crypto Copilot, looks like a normal trading tool but quietly adds an extra transfer to every trade. How the Fake Extension Works Socket’s Threat Research Team found that Crypto Copilot has been available on the Chrome Web Store since June 2024. It advertises itself as a tool that lets people trade Solana tokens directly from their X feed. The extension shows token prices, connects to popular wallets, and looks completely safe on the surface. However, when a user performs a swap, the extension builds the normal Raydium swap instruction and then secretly adds a second instruction. The extra instruction sends SOL to an attacker controlled wallet without telling the user. The minimum amount taken is 0.0013 SOL, or 0.05 percent of the swap size if the trade is large enough. Wallets usually show only the main summary of a transaction. Most users will not expand the full instruction list, so they will not notice that two separate actions are being signed at once. Looks legit on the outside; suspicious inside Crypto Copilot tries hard to appear like a real and helpful product. It detects token names on X, shows DexScreener data, and supports well known wallets such as Phantom and Solflare. It also asks only for common wallet permissions. But the backend reveals the truth.… The post Chrome Extension Exposed for Injecting Hidden SOL Fees appeared on BitcoinEthereumNews.com. The Hack: A Chrome extension named “Crypto Copilot” secretly adds a fee transfer to user swaps. The Trick: It hides a SystemProgram.transfer instruction inside legitimate Raydium transactions. The Fix: Users must verify individual transaction instructions in their wallet preview before signing. A malicious browser extension masquerading as a Solana trading tool has been caught siphoning funds from users by silently modifying transaction payloads. Security researchers identified the harmful Chrome extension to secretly steal small amounts of SOL from Solana users during swaps. The extension, named Crypto Copilot, looks like a normal trading tool but quietly adds an extra transfer to every trade. How the Fake Extension Works Socket’s Threat Research Team found that Crypto Copilot has been available on the Chrome Web Store since June 2024. It advertises itself as a tool that lets people trade Solana tokens directly from their X feed. The extension shows token prices, connects to popular wallets, and looks completely safe on the surface. However, when a user performs a swap, the extension builds the normal Raydium swap instruction and then secretly adds a second instruction. The extra instruction sends SOL to an attacker controlled wallet without telling the user. The minimum amount taken is 0.0013 SOL, or 0.05 percent of the swap size if the trade is large enough. Wallets usually show only the main summary of a transaction. Most users will not expand the full instruction list, so they will not notice that two separate actions are being signed at once. Looks legit on the outside; suspicious inside Crypto Copilot tries hard to appear like a real and helpful product. It detects token names on X, shows DexScreener data, and supports well known wallets such as Phantom and Solflare. It also asks only for common wallet permissions. But the backend reveals the truth.…

Chrome Extension Exposed for Injecting Hidden SOL Fees

  • The Hack: A Chrome extension named “Crypto Copilot” secretly adds a fee transfer to user swaps.
  • The Trick: It hides a SystemProgram.transfer instruction inside legitimate Raydium transactions.
  • The Fix: Users must verify individual transaction instructions in their wallet preview before signing.

A malicious browser extension masquerading as a Solana trading tool has been caught siphoning funds from users by silently modifying transaction payloads.

Security researchers identified the harmful Chrome extension to secretly steal small amounts of SOL from Solana users during swaps. The extension, named Crypto Copilot, looks like a normal trading tool but quietly adds an extra transfer to every trade.

How the Fake Extension Works

Socket’s Threat Research Team found that Crypto Copilot has been available on the Chrome Web Store since June 2024. It advertises itself as a tool that lets people trade Solana tokens directly from their X feed. The extension shows token prices, connects to popular wallets, and looks completely safe on the surface.

However, when a user performs a swap, the extension builds the normal Raydium swap instruction and then secretly adds a second instruction. The extra instruction sends SOL to an attacker controlled wallet without telling the user. The minimum amount taken is 0.0013 SOL, or 0.05 percent of the swap size if the trade is large enough.

Wallets usually show only the main summary of a transaction. Most users will not expand the full instruction list, so they will not notice that two separate actions are being signed at once.

Looks legit on the outside; suspicious inside

Crypto Copilot tries hard to appear like a real and helpful product. It detects token names on X, shows DexScreener data, and supports well known wallets such as Phantom and Solflare. It also asks only for common wallet permissions.

But the backend reveals the truth. The extension sends data to a domain that has no real website and only displays a blank page. Its official website is parked and does not host any working product. Even the backend domain has a spelling mistake in its name. These details show that the creators did not plan to build a real trading service.

The code is also heavily hidden and difficult to read. Key parts, including the attacker’s wallet address, are buried inside long and confusing scripts.

The Hidden Fees Add Up Over Time

The extension charges users in two ways. For swaps under 2.6 SOL, it takes the minimum 0.0013 SOL. For trades above that amount, it takes 0.05 percent of the swap. For example, a 100 SOL trade would secretly send 0.05 SOL to the attacker.

Related: Trump-Backed Crypto Firm Loses Another CEO After $1.5 Billion Token Deal

So far, the attacker has not collected much ($6.86), which shows  that the extension has not yet spread widely. But the system is designed to scale, meaning that larger or frequent traders could lose significant amounts without knowing.

Warning for Solana Users

Researchers say this extension was never meant to operate as a real product. It only exists to look trustworthy while taking fees in the background. Users are advised to avoid unknown browser extensions, especially those that ask for wallet access or promise one click trading.

“Install wallet extensions only from verified publisher pages, not Chrome Web Store search results,” the research said.

Related: Ethereum Increases Gas Limit to 60M, Scaling Base Layer Ahead of Fusaka Upgrade

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/malicious-chrome-extension-crypto-copilot-caught-injecting-hidden-fees-into-solana-swaps/

Market Opportunity
Solana Logo
Solana Price(SOL)
$146.7
$146.7$146.7
-0.24%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum price predictions are turning heads, with analysts suggesting ETH could climb to $10,000 by 2026 as institutional demand and network upgrades drive growth. While Ethereum remains a blue-chip asset, investors looking for sharper multiples are eyeing Layer Brett (LBRETT). Currently in presale at just $0.0058, the Ethereum Layer 2 meme coin is drawing huge [...] The post Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058 appeared first on Blockonomi.
Share
Blockonomi2025/09/17 23:45
‘Primal’ Creator Genndy Tartakovsky Talks Zombified Season 3

‘Primal’ Creator Genndy Tartakovsky Talks Zombified Season 3

The post ‘Primal’ Creator Genndy Tartakovsky Talks Zombified Season 3 appeared on BitcoinEthereumNews.com. A zombified Spear appears in Season 3 of Adult Swim’s
Share
BitcoinEthereumNews2026/01/15 06:04
‘Dr. Quinn’ Co-Stars Jane Seymour And Joe Lando Reuniting In New Season Of ‘Harry Wild’

‘Dr. Quinn’ Co-Stars Jane Seymour And Joe Lando Reuniting In New Season Of ‘Harry Wild’

The post ‘Dr. Quinn’ Co-Stars Jane Seymour And Joe Lando Reuniting In New Season Of ‘Harry Wild’ appeared on BitcoinEthereumNews.com. Joe Lando and Janey Seymour in “Harry Wild.” Courtesy: AMC / Acorn Jane Seymour is getting her favorite frontier friend to join her in her latest series. In the mid-90s Seymour spent six seasons as Dr. Micheala Quinn on Dr. Quinn, Medicine Woman. During the run of the series, Dr. Quinn met, married, and started a family with local frontiersman Byron Sully, also known simply as Sully, played by Joe Lando. Now, the duo will once again be partnering up, but this time to solve crimes in Seymour’s latest show, Harry Wild. In the series, literature professor Harriet ‘Harry’ Wild found herself at crossroads, having difficulty adjusting to retirement. After a stint staying with her police detective son, Charlie, Harry begins to investigate crimes herself, now finding an unlikely new sleuthing partner, a teen who had mugged Harry. In the upcoming fifth season, now in production in Dublin, Ireland, Lando will join the cast, playing Pierce Kennedy, the new State Pathologist, who becomes a charming and handsome natural ally for Harry. Promotional portrait of British actress Jane Seymour (born Joyce Penelope Wilhelmina Frankenberg), as Dr. Michaela ‘Mike’ Quinn, and American actor Joe Lando, as Byron Sully, as they pose with horses for the made-for-tv movie ‘Dr. Quinn, Medicine Woman: the Movie,’ 1999. (Photo by Spike Nannarello/CBS Photo Archive/Getty Images) Getty Images Emmy-Award Winner Seymour also serves as executive producer on the series. The new season finds Harry and Fergus delving into the worlds of whiskey-making, theatre and musical-tattoos, chasing a gang of middle-aged lady burglars and working to deal with a murder close to home. Debuting in 2026, Harry Wild Season 5 will consist of six episodes. Ahead of the new season, a 2-part Harry Wild Special will debut exclusively on Acorn TV on Monday, November 24th. Source: https://www.forbes.com/sites/anneeaston/2025/09/17/dr-quinn-co-stars-jane-seymour-and-joe-lando-reuniting-in-new-season-of-harry-wild/
Share
BitcoinEthereumNews2025/09/18 07:05