Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’

    December 18, 2025

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    World Network is still 988 million sign-ups short of its 1 billion-user goal

    December 18, 2025
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

    Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

    Isabella TaylorBy Isabella TaylorNovember 28, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks.

    Summary

    • Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​
    • Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​
    • Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification.

    A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team.

    The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address.

    Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated.

    The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said.

    A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms.

    Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users approve what appears to be a single transaction, according to the report.

    Solana browser extension Crypto Copilot studied by Socket

    Although installation numbers remain low, Socket warned that cumulative losses pose significant risks for frequent traders. Incremental fund diversions may accumulate undetected, illustrating broader security threats posed by browser-based cryptocurrency tools, the firm stated.

    Previous incidents have involved malicious Chrome and Firefox extensions targeting cryptocurrency wallets including MetaMask, Phantom, and Coinbase, according to industry reports.

    The incident highlights vulnerabilities in browser-based cryptocurrency security and the importance of transaction verification before approval, Socket stated. As browser-based tools increasingly integrate cryptocurrency trading functionality, enhanced monitoring and oversight of Chrome’s extension ecosystem may be necessary to protect decentralized finance users, the report concluded.

    Solana traders are advised to verify extension legitimacy, review transaction instructions in detail, and monitor updates from cybersecurity researchers, according to Socket.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Isabella Taylor

    Related Posts

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    Bitcoin bulls test B3’s tokenized RWA and stablecoin bet

    December 18, 2025

    Coinbase expands trading into stocks and prediction markets

    December 18, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’

    Altcoins December 18, 2025

    A popular crypto analyst believes a privacy-focused altcoin is heading to new all-time highs even…

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    World Network is still 988 million sign-ups short of its 1 billion-user goal

    December 18, 2025

    Bitcoin bulls test B3’s tokenized RWA and stablecoin bet

    December 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    AI Crypto Platform Lithosphere (LITHO) Introduces Ignite, an Automated Launchpad for Ecosystem Discovery

    December 16, 2025

    AGII Introduces Multi-Domain Insight Processor to Enhance Analytical Speed Across Web3 Systems

    December 11, 2025

    AGII Deploys Adaptive Integrity Core for Autonomous Contract-Level Verification

    December 10, 2025

    AGII Launches Predictive Threshold Engine to Strengthen Data-Driven Blockchain Intelligence

    December 8, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    Crypto wrap: Bitcoin’s sharp fall drags Ethereum, XRP, Solana and BNB lower

    October 19, 2025

    Imagen Network to Support Kadena Chainweb EVM for Enhanced Interoperability

    October 23, 2025

    Bitcoin’s institutional surge widens trillion-dollar gap with altcoins

    October 25, 2025

    Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’

    December 18, 2025

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    World Network is still 988 million sign-ups short of its 1 billion-user goal

    December 18, 2025
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    Demo
    Top Posts

    AGII Launches Hybrid Logic Engine to Strengthen Predictive Web3 Infrastructure Control

    December 1, 20251 Views

    AGII Deploys Multi-Threaded Decision Layer to Advance High-Speed Blockchain Intelligence

    November 26, 20251 Views

    AGII Enhances Predictive Intelligence to Strengthen Smart Contract Reliability

    November 19, 20251 Views

    AI Crypto Platform Lithosphere (LITHO) Introduces Ignite, an Automated Launchpad for Ecosystem Discovery

    December 16, 20250 Views
    Don't Miss

    Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’

    Altcoins December 18, 2025

    A popular crypto analyst believes a privacy-focused altcoin is heading to new all-time highs even…

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    World Network is still 988 million sign-ups short of its 1 billion-user goal

    December 18, 2025

    Bitcoin bulls test B3’s tokenized RWA and stablecoin bet

    December 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Coinbase spends $17k per day to protect Brian Armstrong from tequila

    December 3, 20253 Views

    Apex Fusion expands to Base with bAP3X token deployment

    December 3, 20253 Views

    FOIA reveals US Marshals sitting on at least $1.6B in BTC

    December 3, 20253 Views

    Kraken buys Backed Finance, expands tokenized stock platform

    December 3, 20253 Views
    Don't Miss

    Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’

    Altcoins December 18, 2025

    A popular crypto analyst believes a privacy-focused altcoin is heading to new all-time highs even…

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    World Network is still 988 million sign-ups short of its 1 billion-user goal

    December 18, 2025

    Bitcoin bulls test B3’s tokenized RWA and stablecoin bet

    December 18, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’

    December 18, 2025

    Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs

    December 18, 2025

    World Network is still 988 million sign-ups short of its 1 billion-user goal

    December 18, 2025
    Recent Posts
    • Analyst Says One Privacy-Focused Altcoin Building Two-Year Parabolic Trend: ‘The Best Chart in Crypto’
    • Monero bulls eye 80%+ rally as two-year parabolic trend nears all-time highs
    • World Network is still 988 million sign-ups short of its 1 billion-user goal
    • Bitcoin bulls test B3’s tokenized RWA and stablecoin bet
    • Richard Heart pokes MakerDAO to ‘do the funniest thing’ and rug-pull
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.