Solana Traders Targeted by Months-Long Browser Malware That Intercepted All Swaps

A malicious Chrome extension posing as a Solana trading assistant has quietly siphoned fees from user swaps for months, exploiting the way wallet interfaces bundle transactions.

The extension, named Crypto Copilot, had been available on the Chrome Web Store since June as a convenience tool for traders on the Solana DEX Raydium. It injected a hidden second instruction into every Raydium swap, sending either 0.0013 SOL or 0.05% of the trade value to an attacker-controlled wallet.

The exploit worked because wallet interfaces typically present multiple instructions as a single atomic transaction. Users unknowingly signed off on both the intended swap and the hidden transfer—similar to pressing “confirm” on an order that secretly charges for extra items without notice.

Cybersecurity firm Socket, which flagged the extension earlier this week, noted that while on-chain data suggests limited adoption so far, the mechanism could scale: trades above 2.6 SOL trigger the 0.05% fee, meaning a 100 SOL swap would lose 0.05 SOL (around $10 at current prices).

Further signs point to a rushed setup. The extension’s main domain, cryptocopilot.app, is parked on GoDaddy, and the backend dashboard at crypto-coplilot-dashboard.vercel.app (with a noticeable misspelling) returns a blank page despite collecting wallet metadata.

Socket has submitted a formal takedown request to Google, though the extension was still live at the time of reporting. Users are advised to avoid closed-source extensions requesting signing privileges and to move assets to new wallets if they interacted with Crypto Copilot.

  • Related Posts

    Binance expands its platform with a prediction market offering for millions of users.

    Binance has added a prediction markets feature to its Binance Wallet, enabling users to trade on real-world event outcomes directly within the app. The integration links Binance Wallet to Predict.fun,…

    Continue reading
    Bhutan has reportedly divested 70% of its Bitcoin over the past 18 months and may have paused or ended BTC mining.

    Bhutan is steadily exiting one of the most closely watched sovereign bitcoin strategies, continuing a measured reduction in its holdings. The kingdom’s reserves have declined from roughly 13,000 BTC in…

    Continue reading