Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Solana News Today: Deceptive Chrome Extension Secretly Drains Solana Assets by Abusing User Trust

Solana News Today: Deceptive Chrome Extension Secretly Drains Solana Assets by Abusing User Trust

Bitget-RWA2025/11/27 21:56
By:Bitget-RWA

- A malicious Chrome extension, Crypto Copilot, secretly siphons 0.0013 SOL or 0.05% from Solana transactions via hidden transfer instructions. - The extension exploits Raydium DEX and obfuscated code to bypass detection, routing fees to attacker-controlled wallets without user awareness. - Despite a takedown request, the extension remains available on Chrome Web Store, highlighting growing browser-based crypto threats affecting 15 users as of 2025. - Cybersecurity experts warn of rising malicious crypto e

Crypto Copilot Chrome Extension Secretly Steals Fees from Solana Trades

A deceptive Google Chrome extension called Crypto Copilot has been exposed for covertly extracting hidden fees from users conducting Solana (SOL) transactions. Promoted as a tool for seamless Solana swaps directly from social media, the extension exploits users’ trust in browser-based trading solutions.

Cybersecurity experts at Socket discovered that Crypto Copilot secretly inserts an extra transfer command into every transaction. This results in a concealed fee—either 0.0013 SOL or 0.05% of the transaction value—being funneled to a wallet controlled by the attacker. The extension’s interface only displays the legitimate swap, effectively hiding the additional on-chain instruction that executes simultaneously.

How the Attack Works

Crypto Copilot utilizes Solana’s decentralized exchange Raydium to process swaps. However, it appends a SystemProgram.transfer instruction to siphon off funds. Unlike traditional wallet-draining attacks that empty entire balances, this extension quietly skims a small amount from each trade, making detection more difficult.

The malicious code is heavily obfuscated to avoid security scans, and its backend is hosted on a seemingly inactive domain. The main website is currently parked, further masking its true purpose. Despite a removal request sent to Google, the extension remains available on the Chrome Web Store since June 18, 2024, and has reportedly been installed by at least 15 users as of November 2025.

Rising Threats from Malicious Extensions

This incident highlights a growing wave of attacks leveraging browser extensions within the cryptocurrency sector. In recent months, similar tactics have been used by other extensions, including a popular wallet tool and a Jupiter DEX aggregator, both of which have been implicated in draining Solana wallets.

According to industry reports, an 18-month investigation uncovered 186 crypto-related malicious extensions, many of which evaded antivirus detection for extended periods. With the Chrome extension ecosystem reaching over 3 billion devices, these threats can spread rapidly, often using misleading permissions or cloned interfaces to deceive users.

Protecting Yourself from Extension-Based Scams

The stealthy fee skimming by Crypto Copilot can lead to significant losses, especially for frequent traders. Security professionals recommend several precautions:

  • Carefully review all transaction details before approving any operation.
  • Refrain from installing unverified or suspicious browser extensions.
  • Regularly audit installed extensions for unnecessary permissions.
  • Check wallet connection histories for unusual activity.
  • Enable transaction simulation features on Solana explorers to spot irregularities.

Broader Security Concerns in DeFi

This case also underscores persistent security challenges in decentralized finance (DeFi) applications. While Solana’s ecosystem continues to expand with major upgrades like Firedancer and Alpenglow, vulnerabilities in user-facing tools remain a significant risk. As both institutional and retail investors increasingly use crypto ETFs and multi-chain wallets, comprehensive security audits and ongoing user education are essential to reduce exposure to such threats.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin News Today: Bitcoin Faces a Pivotal Week: Optimistic Buying Meets Bearish Whales Amid Economic Uncertainty

- Bitcoin stabilizes near $87,000 after 11-day selloff, with analysts divided on whether the rebound signals a trend reversal or temporary relief. - US ETFs record $1.22B in outflows amid weak institutional demand, compounded by macroeconomic uncertainty and delayed Fed rate-cut expectations. - Technical indicators show mixed signals: RSI suggests waning bearish momentum, while a "Death Cross" pattern historically precedes deep corrections. - Institutional accumulation by mid-sized wallets contrasts with w

Bitget-RWA2025/11/28 02:38
Bitcoin News Today: Bitcoin Faces a Pivotal Week: Optimistic Buying Meets Bearish Whales Amid Economic Uncertainty

Dogecoin News Today: Dogecoin's ETF Ambitions Face Off Against Technical Downturn Amid Market Turbulence

- Dogecoin (DOGE) faces technical collapse after breaking below key support levels and moving averages, driven by 263% above-average volume and algorithmic selling. - Unexpected resilience emerges as DOGE rallies 2.6% post-Musk's D.O.G.E. initiative dissolution and gains 0.7% amid new spot ETF approvals like Grayscale's GDOG . - Broader crypto markets remain bearish with Bitcoin below $85,000 and $120B lost in 24 hours, while DOGE futures open interest surges 3.27% signaling speculative activity. - Analyst

Bitget-RWA2025/11/28 02:38
Dogecoin News Today: Dogecoin's ETF Ambitions Face Off Against Technical Downturn Amid Market Turbulence

AI’s Core Economic Transformation: Entrée Capital Allocates $300 Million to Advanced Technology

- Entrée Capital launches $300M fund targeting AI, deep-tech, and crypto, boosting total AUM to $1.5B. - Focus on vertical AI, quantum computing, and decentralized infrastructure to transform lagging sectors like manufacturing. - C3.ai deepens Microsoft partnership to integrate enterprise AI tools, enabling unified data operations on Azure. - C3.ai reports 21% YoY revenue growth ($87.2M Q1) as AI demand rises, but analysts warn of market immaturity risks. - Strategic bets on AI-driven innovation highlight

Bitget-RWA2025/11/28 02:38

Evaluating the Lasting Investment Impact of Zero-Knowledge Scaling on Ethereum Ecosystems

- ZK-based Layer 2 market grows rapidly, with $28B TVL in 2025 and 60.7% CAGR projected to reach $90B by 2031. - ZKsync, StarkNet, and Polygon zkEVM lead by slashing fees and offering EVM compatibility, attracting institutional partnerships. - ZKsync's Atlas upgrade (15,000 TPS) and GKR protocol (43,000 TPS) highlight efficiency gains via Buterin's "kappa" metric. - Ethereum's Fusaka roadmap, including PeerDAS and Verkle Trees, aligns with ZK scaling goals, boosting STRK and ZK token valuations.

Bitget-RWA2025/11/28 02:38
Evaluating the Lasting Investment Impact of Zero-Knowledge Scaling on Ethereum Ecosystems