By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
  • Football
  • NFL
  • MMA
  • Formula 1
  • Sport News
  • NBA
omisnews.com
  • Home
  • NFL

    NFL

    Show More
  • MMA
  • Football

    Football

    Show More
  • NBA

    NBA

    Show More
  • Pages
    • Blog Index
    • Contact
    • Search Page
    • 404 Page
Reading: Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap
omisnews.comomisnews.com
Font ResizerAa
  • Football
  • NFL
  • MMA
  • Formula 1
  • Sport News
  • NBA
Search
  • Home
  • Categories
    • Formula 1
    • MMA
    • Football
    • NFL
    • Sport News
    • NBA
  • More Foxiz
    • Blog Index
    • Sitemap
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Uncategorized

Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap

OmisNews
Last updated: November 27, 2025 7:15 pm
OmisNews
6 Min Read
Share


Contents
Crypto Copilot Sends Wallet Data to Suspicious Backend While Draining Trader FundsCrypto Losses Fall to 2025 Lows, but Browser Extension Attacks Continue to Climb

A newly discovered malicious Chrome extension is stealing funds from Solana traders by quietly siphoning a fee from every swap they execute, according to new findings from Socket’s Threat Research Team.

The extension, called Crypto Copilot, has been available on the Chrome Web Store since June 2024 and markets itself as a shortcut for executing Solana trades directly from users’ X feeds.

Behind the interface, however, researchers found code designed to insert an additional transfer into each Raydium swap, diverting at least 0.0013 SOL, or 0.05% of each transaction, to an attacker-controlled wallet.

Source: Socket

Crypto Copilot Sends Wallet Data to Suspicious Backend While Draining Trader Funds

Socket researchers say the extension constructs a normal Raydium swap instruction but then appends a second instruction that transfers SOL to the wallet address Bjeida.

Users only see the legitimate swap in the interface, and most wallet confirmation windows display only a high-level summary of the transaction rather than the full list of instructions.

As a result, traders approve what appears to be a standard transaction, unaware of the hidden transfer embedded inside it.

The fee logic is fully hardcoded inside the extension and buried under layers of obfuscated JavaScript.

Socket notes that the extension applies whichever is greater between the minimum fee and the percentage-based fee, meaning trades above 2.6 SOL incur the full 0.05% extraction.

Researchers found that the extension uses variable renaming and aggressive minification to conceal the behavior, and the attacker’s wallet is labeled under an innocuous variable deep inside the bundle.

The extension remains online at the time of reporting. Socket says it has submitted a takedown request to Google, but has not received confirmation that action has been taken.

Beyond the fee theft, investigators also discovered that Crypto Copilot connects to a backend hosted on crypto-coplilot-dashboard.vercel.app, a misspelled domain that shows only a blank placeholder page.

Source: Socket

Despite the empty site, the extension regularly sends connected wallet identifiers and activity data to this backend, along with using a hardcoded Helius API key for transaction simulation and RPC calls.

A separate domain tied to the tool, cryptocopilot.app, is currently parked.

Researchers say the absence of documentation, a functioning dashboard, or any supporting infrastructure is inconsistent with a legitimate trading product and instead reflects common practices seen in malicious browser extensions.

While on-chain activity linked to the attacker’s wallet remains limited, investigators believe the low transaction volume likely reflects the extension’s relatively small distribution rather than an absence of risk.

They warn that the mechanism scales with trading activity, meaning high-volume users could lose larger amounts over time without noticing the incremental drain.

Crypto Losses Fall to 2025 Lows, but Browser Extension Attacks Continue to Climb

The discovery comes during a period of heightened scrutiny around browser-based crypto threats. In July, more than 40 malicious Firefox extensions were found impersonating major wallet providers, including MetaMask, Coinbase, Phantom, OKX, and Trust Wallet.

👾 Koi Security exposes 40+ malicious crypto wallet extensions in Firefox store targeting seed phrases from @coinbase, @MetaMask, and @TrustWallet as crypto losses explode to $2.2B in 2025.#CryptoWallet #Hackhttps://t.co/0EcvDev8SY

— Cryptonews.com (@cryptonews) July 3, 2025

Those extensions harvested wallet credentials directly from users’ browsers and transmitted them to attacker-controlled servers.

Exchanges such as OKX publicly warned users and filed complaints after discovering fake plugins masquerading as official wallet tools. Browser extensions have emerged as one of the most persistent attack vectors in 2025, contributing to a growing share of crypto losses.

Wallet-related breaches accounted for $1.7 billion of the $2.2 billion stolen across the first half of the year, according to CertiK. Phishing incidents added another $410 million.

Despite the rise in extension-based threats, the broader crypto sector briefly experienced a decline in successful hacks.

PeckShield recorded just $18.18 million stolen across 15 incidents in October, the lowest monthly total of the year.

🔻 Crypto exploits plunged 22% in September, but losses still totaled $127M. The largest attacks hit $UXLINK ($44M) and @swissborg ($41.5M), according to data from @PeckShieldAlert. #crypto #DeFi #hackshttps://t.co/FsrFl0qJaw

— Cryptonews.com (@cryptonews) October 2, 2025

That figure had been far higher a month earlier when losses reached $127.06 million in September, driven by nearly 20 major exploits. But even as overall losses dipped, high-profile breaches continued.

The post Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap appeared first on Cryptonews.





Source link

Share This Article
Facebook Email Copy Link Print
Previous Article Has Crypto Fear Peaked? KAS, FLR, SKY Rise While Caution Lingers In Altcoin Season
Next Article Solana ETFs Hit $8M Outflow, Break 21-Day Inflow Streak – What’s Next?
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Most Popular

A Memoir of Soccer, Grit, and Leveling the Playing Field
10 Super Easy Steps to Your Dream Body 4X
Mind Gym : An Athlete's Guide to Inner Excellence
Mastering The Terrain Racing, Courses and Training

Shiba Inu Price Prediction: 61 Million SHIB Burned Overnight – Major Supply Shock Coming?

By OmisNews

Subscribe Now

Subscribe to our newsletter to get our newest articles instantly!

Bitcoin ETF Becomes Harvard’s Top Holding After 257% Stake Increase

2 weeks ago

Missed the ASTER Price Pump? This New Crypto Project Could Outperform Soon

2 weeks ago

You Might Also Like

Uncategorized

Saylor Dismisses Stablecoin Threat to Bitcoin’s $1.2M Path

1 week ago
Uncategorized

BlockchainFX Furthers Multi-Market Access Tools

1 week ago
Uncategorized

[LIVE] U.S. Employment Report Released: September Jobs Data Shows 119K Payrolls Added as Bitcoin Holds $92K – Can Crypto Markets Rally?

1 week ago
Uncategorized

Tether Ceases Operations in Uruguay Citing High Energy Costs

4 days ago

Sport News

  • Basketball
  • Baseball
  • Football
  • Hockey
  • Aquatics

Socials

Facebook Twitter Youtube

Company

  • About Us
  • Children
  • Contact Us
  • Our Edge
  • Case Studies
  • Advertise with us
  • Newsletters
  • Deal

Made by ThemeRuby using the Foxiz theme. Powered by WordPress

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?