Solana Traders Targeted by Months-Long Browser Malware That Intercepted All Swaps

A malicious Chrome extension posing as a Solana trading assistant has quietly siphoned fees from user swaps for months, exploiting the way wallet interfaces bundle transactions.

The extension, named Crypto Copilot, had been available on the Chrome Web Store since June as a convenience tool for traders on the Solana DEX Raydium. It injected a hidden second instruction into every Raydium swap, sending either 0.0013 SOL or 0.05% of the trade value to an attacker-controlled wallet.

The exploit worked because wallet interfaces typically present multiple instructions as a single atomic transaction. Users unknowingly signed off on both the intended swap and the hidden transfer—similar to pressing “confirm” on an order that secretly charges for extra items without notice.

Cybersecurity firm Socket, which flagged the extension earlier this week, noted that while on-chain data suggests limited adoption so far, the mechanism could scale: trades above 2.6 SOL trigger the 0.05% fee, meaning a 100 SOL swap would lose 0.05 SOL (around $10 at current prices).

Further signs point to a rushed setup. The extension’s main domain, cryptocopilot.app, is parked on GoDaddy, and the backend dashboard at crypto-coplilot-dashboard.vercel.app (with a noticeable misspelling) returns a blank page despite collecting wallet metadata.

Socket has submitted a formal takedown request to Google, though the extension was still live at the time of reporting. Users are advised to avoid closed-source extensions requesting signing privileges and to move assets to new wallets if they interacted with Crypto Copilot.

  • Related Posts

    Bitcoin’s downside may be limited if gold comparison signals a bottom, analyst notes

    Bitcoin’s correction could extend into late 2026 in dollar terms, but its valuation against gold suggests the market may be closer to a turning point, according to research from Mercado…

    Continue reading
    SpaceX’s once-$780M bitcoin treasury now valued near $545M as IPO filing looms

    SpaceX holds roughly 8,285 bitcoin in custody with Coinbase Prime, a position now worth about $545 million after losing approximately $235 million in value over the past three months. For…

    Continue reading