Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Markets>
Solana News Today: Deceptive Chrome Extension Secretly Drains Solana Assets by Abusing User Trust

Solana News Today: Deceptive Chrome Extension Secretly Drains Solana Assets by Abusing User Trust

Bitget-RWA2025/11/27 21:56
By: Bitget-RWA
- A malicious Chrome extension, Crypto Copilot, secretly siphons 0.0013 SOL or 0.05% from Solana transactions via hidden transfer instructions. - The extension exploits Raydium DEX and obfuscated code to bypass detection, routing fees to attacker-controlled wallets without user awareness. - Despite a takedown request, the extension remains available on Chrome Web Store, highlighting growing browser-based crypto threats affecting 15 users as of 2025. - Cybersecurity experts warn of rising malicious crypto e

Crypto Copilot Chrome Extension Secretly Steals Fees from Solana Trades

A deceptive Google Chrome extension called Crypto Copilot has been exposed for covertly extracting hidden fees from users conducting Solana (SOL) transactions. Promoted as a tool for seamless Solana swaps directly from social media, the extension exploits users’ trust in browser-based trading solutions.

Cybersecurity experts at Socket discovered that Crypto Copilot secretly inserts an extra transfer command into every transaction. This results in a concealed fee—either 0.0013 SOL or 0.05% of the transaction value—being funneled to a wallet controlled by the attacker. The extension’s interface only displays the legitimate swap, effectively hiding the additional on-chain instruction that executes simultaneously.

How the Attack Works

Crypto Copilot utilizes Solana’s decentralized exchange Raydium to process swaps. However, it appends a SystemProgram.transfer instruction to siphon off funds. Unlike traditional wallet-draining attacks that empty entire balances, this extension quietly skims a small amount from each trade, making detection more difficult.

The malicious code is heavily obfuscated to avoid security scans, and its backend is hosted on a seemingly inactive domain. The main website is currently parked, further masking its true purpose. Despite a removal request sent to Google, the extension remains available on the Chrome Web Store since June 18, 2024, and has reportedly been installed by at least 15 users as of November 2025.

Rising Threats from Malicious Extensions

This incident highlights a growing wave of attacks leveraging browser extensions within the cryptocurrency sector. In recent months, similar tactics have been used by other extensions, including a popular wallet tool and a Jupiter DEX aggregator, both of which have been implicated in draining Solana wallets.

According to industry reports, an 18-month investigation uncovered 186 crypto-related malicious extensions, many of which evaded antivirus detection for extended periods. With the Chrome extension ecosystem reaching over 3 billion devices, these threats can spread rapidly, often using misleading permissions or cloned interfaces to deceive users.

Protecting Yourself from Extension-Based Scams

The stealthy fee skimming by Crypto Copilot can lead to significant losses, especially for frequent traders. Security professionals recommend several precautions:

Broader Security Concerns in DeFi

This case also underscores persistent security challenges in decentralized finance (DeFi) applications. While Solana’s ecosystem continues to expand with major upgrades like Firedancer and Alpenglow, vulnerabilities in user-facing tools remain a significant risk. As both institutional and retail investors increasingly use crypto ETFs and multi-chain wallets, comprehensive security audits and ongoing user education are essential to reduce exposure to such threats.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Astar (ASTR) Price Rally: Rising Interest in Blockchain Infrastructure and Cross-Chain Operations

- Astar (ASTR) surges in 2025 due to institutional adoption, technical upgrades, and cross-chain interoperability. - Its 2.0 upgrade enables 150,000 TPS, scalable to 300,000 via JAM protocol, while dynamic tokenomics balances inflation with burning. - Partnerships with Sony , Toyota , and Japan Airlines drive real-world blockchain applications like tokenized loyalty programs. - Astar maintains $2.38M TVL amid DeFi contraction, leveraging cross-chain infrastructure and enterprise-grade reliability. - Future

Bitget-RWA2025/11/29 03:10
Astar 2.0’s New Direction: Driving DeFi Innovation and Attracting Institutional Participation

- Astar 2.0 introduces fixed-supply tokenomics, interoperability upgrades, and decentralized governance to attract institutional investors and redefine DeFi. - Tokenomics 3.0 caps ASTR supply at 10.5B, reducing inflation risks and aligning with Bitcoin’s scarcity model to boost institutional confidence. - Plaza and Startale App enhance cross-chain asset flows and user accessibility, addressing scalability and onboarding barriers for institutions. - Governance reforms shift to community-driven councils by 2

Bitget-RWA2025/11/29 03:10
Ethereum News Today: Ethereum Faces a Scaling Challenge: Striving for Both Efficiency and Decentralization

- Ethereum's gas limit surged to 60 million (a four-year high), supported by 513,000+ validators to enhance throughput and reduce congestion. - Developers aim to triple the limit to 180 million, with Vitalik Buterin proposing a 5x increase via optimized gas pricing for efficiency. - The Fusaka upgrade (Dec 3, 2025) will codify this change, boosting Layer 1 throughput by 33% and Layer 2 by 133%. - Ethereum prioritizes targeted scaling over fee wars, maintaining decentralization while enabling sub-cent trans

Bitget-RWA2025/11/29 03:08
Bitcoin News Today: While U.S. markets take a break for Thanksgiving, the nonstop nature of crypto fuels a $90K rally in Bitcoin

- U.S. crypto markets surged as Bitcoin (BTC) hit $90,000 during Thanksgiving 2025, defying traditional market closures. - Price rebound followed November losses, with analysts linking BTC/ETH/SOL gains to potential Fed rate cuts and improved liquidity. - Turkmenistan legalized crypto trading under strict state control, mandating licensing and cold storage while banning bank involvement. - Innovations like Avail's cross-chain liquidity platform and Bybit's CEX-integrated liquidity farms highlighted sector

Bitget-RWA2025/11/29 03:08

Trending news

More
1
Astar (ASTR) Price Rally: Rising Interest in Blockchain Infrastructure and Cross-Chain Operations
2
Astar 2.0’s New Direction: Driving DeFi Innovation and Attracting Institutional Participation

Crypto prices

More
Bitcoin
Bitcoin
BTC
$90,831.21
-0.32%
Ethereum
Ethereum
ETH
$3,032.15
+0.75%
Tether USDt
Tether USDt
USDT
$1
+0.01%
XRP
XRP
XRP
$2.18
-0.15%
BNB
BNB
BNB
$885.93
-0.98%
Solana
Solana
SOL
$137.29
-1.60%
USDC
USDC
USDC
$0.9997
-0.02%
TRON
TRON
TRX
$0.2812
+0.39%
Dogecoin
Dogecoin
DOGE
$0.1502
-0.49%
Cardano
Cardano
ADA
$0.4182
-1.59%
How to buy BTC
Bitget lists BTC – Buy or sell BTC quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter