Close Menu
    Facebook X (Twitter) Instagram
    Facebook Instagram YouTube
    Crypto Go Lore News
    Subscribe
    Tuesday, May 26
    • Home
    • Market Analysis
    • Latest
      • Bitcoin News
      • Ethereum News
      • Altcoin News
      • Blockchain News
      • NFT News
      • Market Analysis
      • Mining News
      • Technology
      • Videos
    • Trending Cryptos
    • AI News
    • Market Cap List
    • Mining
    • Trading
    • Contact
    Crypto Go Lore News
    Home»Trending Cryptos»Malware Chrome Extension Secretly Siphoned Fees From Solana Traders for Months
    Trending Cryptos

    Malware Chrome Extension Secretly Siphoned Fees From Solana Traders for Months

    CryptoExpertBy CryptoExpertNovember 27, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Malware Chrome Extension Secretly Siphoned Fees From Solana Traders for Months
    Share
    Facebook Twitter Pinterest Email Copy Link
    Coinmama



    In brief

    Chrome extension Crypto Copilot secretly adds a hidden SOL transfer to every Raydium swap, siphoning fees to an attacker’s wallet.
    Security platform Socket found the extension uses obfuscated code and a misspelled, inactive backend domain to mask its activity.
    On-chain theft remains small so far, but the mechanism scales with trade size, and the extension is still live on the Chrome Web Store.

    A Chrome extension marketed as a convenient trading tool has been secretly siphoning SOL from users’ swaps since last June, injecting hidden fees into every transaction while masquerading as a legitimate Solana trading assistant.

    Cybersecurity firm Socket discovered malware extension Crypto Copilot during “continuous monitoring” of the Chrome Web Store, security engineer and researcher Kush Pandya told Decrypt.

    🚨 Socket researchers uncovered a malicious Chrome extension that injects hidden #SOL transfers into Raydium swaps, quietly siphoning fees to an attacker wallet.

    Full analysis → https://t.co/bdGOXViJpA #Solana

    — Socket (@SocketSecurity) November 25, 2025

    In an analysis of the malicious extension published Wednesday, Pandya wrote that Crypto Copilot quietly appends an extra transfer instruction to every Solana swap, extracting a minimum of 0.0013 SOL or 0.05% of the trade amount to an attacker-controlled wallet.

    Binance

    “Our AI scanner flagged multiple indicators: aggressive code obfuscation, a hardcoded Solana address embedded in transaction logic, and discrepancies between the extension’s stated functionality and actual network behavior,” Pandya told Decrypt, adding that “These alerts triggered deeper manual analysis that confirmed the hidden fee extraction mechanism.”

    The research points to risks in browser-based crypto tools, particularly extensions that combine social media integration with transaction signing capabilities.

    The extension has remained available on the Chrome Web Store for months, with no warning to users about the undisclosed fees buried in heavily obfuscated code, the report says.

    “The fee behavior is never disclosed on the Chrome Web Store listing, and the logic implementing it is buried inside heavily obfuscated code,” Pandya noted.

    Each time a user swaps tokens, the extension generates the proper Raydium swap instruction but discreetly tacks on an extra transfer directing SOL to the attacker’s address.

    Raydium is a Solana-based decentralized exchange and automated market maker, whereas a “Raydium swap” simply refers to exchanging one token for another through its liquidity pools.

    Users who installed Crypto Copilot, believing it would streamline their Solana trading, have unknowingly been paying hidden fees with every swap, fees that never appeared in the extension’s marketing materials or Chrome Web Store listing.

    The interface shows only the swap details, and wallet pop-ups summarize the transaction, so users sign what looks like a single swap even though both instructions execute simultaneously on-chain.

    The attacker’s wallet has received only small amounts to date, a sign that Crypto Copilot hasn’t reached many users yet, rather than an indication that the exploit is low-risk, as per the report.

    The fee mechanism scales with trade size, as for swaps under 2.6 SOL, the minimum 0.0013 SOL fee applies, and above that threshold, the 0.05% percentage fee takes effect, meaning a 100 SOL swap would extract 0.05 SOL, roughly $10 at current prices.

    The extension’s main domain cryptocopilot[.]app is parked by domain registry GoDaddy, while the backend at crypto-coplilot-dashboard[.]vercel[.]app, notably misspelled, displays only a blank placeholder page despite collecting wallet data, the report says.

    

    Socket has submitted a takedown request to Google’s Chrome Web Store security team, though the extension remained available at the time of publication.

    The platform has urged users to review each instruction before signing transactions, avoid closed-source trading extensions requesting signing permissions, and migrate assets to clean wallets if they installed Crypto Copilot.

    Malware patterns

    Malware remains a growing concern for crypto users. In September, a malware strain called ModStealer was found targeting crypto wallets across Windows, Linux, and macOS through fake job recruiter ads, evading detection by major antivirus engines for almost a month.

    Ledger CTO Charles Guillemet has previously warned that attackers had compromised an NPM developer account, with malicious code attempting to silently swap crypto wallet addresses during transactions across multiple blockchains.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.



    Source link

    Binance
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    CryptoExpert
    • Website

    Related Posts

    Trending Cryptos

    NYT’s Satoshi hunt may have painted a $77B target on a Bitcoin developer

    April 8, 2026
    Trending Cryptos

    Bitcoin Must Clear $69K For Altcoins and BTC To Resume Bull Market

    April 2, 2026
    Trending Cryptos

    BTC USD Price Recovers: Are Trump and Iran Nearing a Peace Deal?

    March 30, 2026
    Trending Cryptos

    Pundit Reveals Why January Will Be A Month For Dogecoin, But Can DOGE Price Reach ATHs?

    December 15, 2025
    Trending Cryptos

    Firedancer is live, but Solana is violating the one safety rule Ethereum treats as non-negotiable

    December 14, 2025
    Trending Cryptos

    Bitcoin, Altcoins Gain Strength But Bears Still Dominate Range Highs

    December 13, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Recommended
    Editors Picks

    Ethereum Sees 56.9% Jump in Transfers as Adoption Gains Ground

    April 12, 2026

    Polymarket Briefly Appears in Google News Before Being Removed

    April 12, 2026

    The Bitcoin miner sell-off looks close to exhaustion marking impending reversal in market pressure

    April 9, 2026

    Uniswap price outlook as Ethereum’s Vitalik Buterin offloads UNI tokens

    April 9, 2026
    Latest Posts

    We are a leading platform dedicated to delivering authoritative insights, news, and resources on cryptocurrencies and blockchain technology. At Crypto Go Lore News, our mission is to empower individuals and businesses with reliable, actionable, and up-to-date information about the cryptocurrency ecosystem. We aim to bridge the gap between complex blockchain technology and practical understanding, fostering a more informed global community.

    Latest Posts

    Ethereum Sees 56.9% Jump in Transfers as Adoption Gains Ground

    April 12, 2026

    Polymarket Briefly Appears in Google News Before Being Removed

    April 12, 2026

    The Bitcoin miner sell-off looks close to exhaustion marking impending reversal in market pressure

    April 9, 2026
    Newsletter

    Subscribe to Updates

    Get the latest Crypto news from Crypto Golore News about crypto around the world.

    Facebook Instagram YouTube
    • Contact
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    © 2026 CryptoGoLoreNews. All rights reserved by CryptoGoLoreNews.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 76,075.00
    ethereum
    Ethereum (ETH) $ 2,076.20
    tether
    Tether (USDT) $ 0.998436
    bnb
    BNB (BNB) $ 656.21
    xrp
    XRP (XRP) $ 1.33
    usd-coin
    USDC (USDC) $ 0.999706
    solana
    Solana (SOL) $ 83.79
    tron
    TRON (TRX) $ 0.374018
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.03
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05