Tuesday, January 13, 2026
No Result
View All Result
The Crypto HODL
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
No Result
View All Result
The Crypto HODL
No Result
View All Result

Malware Chrome Extension Secretly Siphoned Fees From Solana Traders for Months

November 27, 2025
in Web3
Reading Time: 5 mins read
0 0
A A
0
Home Web3
Share on FacebookShare on Twitter



In short

Chrome extension Crypto Copilot secretly provides a hidden SOL switch to each Raydium swap, siphoning charges to an attacker’s pockets.
Safety platform Socket discovered the extension makes use of obfuscated code and a misspelled, inactive backend area to masks its exercise.
On-chain theft stays small up to now, however the mechanism scales with commerce measurement, and the extension remains to be dwell on the Chrome Net Retailer.

A Chrome extension marketed as a handy buying and selling software has been secretly siphoning SOL from customers’ swaps since final June, injecting hidden charges into each transaction whereas masquerading as a authentic Solana buying and selling assistant.

Cybersecurity agency Socket found malware extension Crypto Copilot throughout “steady monitoring” of the Chrome Net Retailer, safety engineer and researcher Kush Pandya advised Decrypt.

🚨 Socket researchers uncovered a malicious Chrome extension that injects hidden #SOL transfers into Raydium swaps, quietly siphoning charges to an attacker pockets.

Full evaluation → https://t.co/bdGOXViJpA #Solana

— Socket (@SocketSecurity) November 25, 2025

In an evaluation of the malicious extension printed Wednesday, Pandya wrote that Crypto Copilot quietly appends an additional switch instruction to each Solana swap, extracting a minimal of 0.0013 SOL or 0.05% of the commerce quantity to an attacker-controlled pockets.

“Our AI scanner flagged a number of indicators: aggressive code obfuscation, a hardcoded Solana deal with embedded in transaction logic, and discrepancies between the extension’s acknowledged performance and precise community habits,” Pandya advised Decrypt, including that “These alerts triggered deeper guide evaluation that confirmed the hidden charge extraction mechanism.”

The analysis factors to dangers in browser-based crypto instruments, notably extensions that mix social media integration with transaction signing capabilities.

The extension has remained out there on the Chrome Net Retailer for months, with no warning to customers in regards to the undisclosed charges buried in closely obfuscated code, the report says.

“The charge habits is rarely disclosed on the Chrome Net Retailer itemizing, and the logic implementing it’s buried inside closely obfuscated code,” Pandya famous.

Every time a consumer swaps tokens, the extension generates the right Raydium swap instruction however discreetly tacks on an additional switch directing SOL to the attacker’s deal with.

Raydium is a Solana-based decentralized alternate and automatic market maker, whereas a “Raydium swap” merely refers to exchanging one token for an additional by its liquidity swimming pools.

Customers who put in Crypto Copilot, believing it might streamline their Solana buying and selling, have unknowingly been paying hidden charges with each swap, charges that by no means appeared within the extension’s advertising and marketing supplies or Chrome Net Retailer itemizing.

The interface reveals solely the swap particulars, and pockets pop-ups summarize the transaction, so customers signal what seems like a single swap despite the fact that each directions execute concurrently on-chain.

The attacker’s pockets has acquired solely small quantities to this point, an indication that Crypto Copilot hasn’t reached many customers but, fairly than a sign that the exploit is low-risk, as per the report.

The charge mechanism scales with commerce measurement, as for swaps underneath 2.6 SOL, the minimal 0.0013 SOL charge applies, and above that threshold, the 0.05% share charge takes impact, that means a 100 SOL swap would extract 0.05 SOL, roughly $10 at present costs.

The extension’s major area cryptocopilot[.]app is parked by area registry GoDaddy, whereas the backend at crypto-coplilot-dashboard[.]vercel[.]app, notably misspelled, shows solely a clean placeholder web page regardless of accumulating pockets information, the report says.



Socket has submitted a takedown request to Google’s Chrome Net Retailer safety crew, although the extension remained out there on the time of publication.

The platform has urged customers to evaluate every instruction earlier than signing transactions, keep away from closed-source buying and selling extensions requesting signing permissions, and migrate belongings to wash wallets in the event that they put in Crypto Copilot.

Malware patterns

Malware stays a rising concern for crypto customers. In September, a malware pressure referred to as ModStealer was discovered concentrating on crypto wallets throughout Home windows, Linux, and macOS by pretend job recruiter adverts, evading detection by main antivirus engines for nearly a month.

Ledger CTO Charles Guillemet has beforehand warned that attackers had compromised an NPM developer account, with malicious code making an attempt to silently swap crypto pockets addresses throughout transactions throughout a number of blockchains.

Day by day Debrief Publication

Begin each day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.



Source link

Tags: ChromeExtensionFeesmalwareMonthsSECRETLYSiphonedSolanaTraders
Previous Post

The Era of Institutional Crypto: How Big Players Are Reshaping Altcoin Utility

Next Post

Solana tokens rip on Upbit after $32M hack due to halted arbitrage

Related Posts

YouTuber Cracks Coca-Cola’s 139-Year-Old Secret Formula—Here ‘s the Recipe
Web3

YouTuber Cracks Coca-Cola’s 139-Year-Old Secret Formula—Here ‘s the Recipe

January 12, 2026
Two major crypto events canceled after city hit by 18 violent physical attacks on crypto holders amid market downturn
Web3

Two major crypto events canceled after city hit by 18 violent physical attacks on crypto holders amid market downturn

January 12, 2026
Bitcoin Shrugs Off Powell Probe as DOJ Targets Fed Chair
Web3

Bitcoin Shrugs Off Powell Probe as DOJ Targets Fed Chair

January 12, 2026
Should Politicians Be Able to Use Prediction Markets? House Bill Proposes Ban
Web3

Should Politicians Be Able to Use Prediction Markets? House Bill Proposes Ban

January 9, 2026
Insiders Say DeepSeek V4 Will Beat Claude and ChatGPT at Coding, Launch Within Weeks
Web3

Insiders Say DeepSeek V4 Will Beat Claude and ChatGPT at Coding, Launch Within Weeks

January 10, 2026
‘Baldur’s Gate 3’ Game Studio Says ‘Divinity’ Won’t Include AI-Generated Art
Web3

‘Baldur’s Gate 3’ Game Studio Says ‘Divinity’ Won’t Include AI-Generated Art

January 10, 2026
Next Post
Solana tokens rip on Upbit after $32M hack due to halted arbitrage

Solana tokens rip on Upbit after $32M hack due to halted arbitrage

Analyst Predicts XRP Price Will Hit $100 Before Bitcoin Hits $1 Million

Analyst Predicts XRP Price Will Hit $100 Before Bitcoin Hits $1 Million

Why BlackRock Still Hasn’t Filed for an XRP ETF Despite Strong Ripple Links

Why BlackRock Still Hasn’t Filed for an XRP ETF Despite Strong Ripple Links

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn Telegram RSS
The Crypto HODL

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at The Crypto HODL

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Mining
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Videos
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Crypto Marketcap

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In