Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

Crypto.NewsCrypto.News2025/11/27 16:00
By:By Andrew FolklerEdited by Dorian Batycka

Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks.

Summary
  • Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions. ​
  • Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands. ​
  • Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification.

A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team.

The extension, named Crypto Copilot, enables users to trade SOL ( SOL ) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address.

Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated.

The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said.

A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms.

Crypto Copilot utilizes Raydium , an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users approve what appears to be a single transaction, according to the report.

Solana browser extension Crypto Copilot studied by Socket

Although installation numbers remain low, Socket warned that cumulative losses pose significant risks for frequent traders. Incremental fund diversions may accumulate undetected, illustrating broader security threats posed by browser-based cryptocurrency tools, the firm stated.

Previous incidents have involved malicious Chrome and Firefox extensions targeting cryptocurrency wallets including MetaMask, Phantom, and Coinbase, according to industry reports.

The incident highlights vulnerabilities in browser-based cryptocurrency security and the importance of transaction verification before approval, Socket stated . As browser-based tools increasingly integrate cryptocurrency trading functionality, enhanced monitoring and oversight of Chrome’s extension ecosystem may be necessary to protect decentralized finance users, the report concluded.

Solana traders are advised to verify extension legitimacy, review transaction instructions in detail, and monitor updates from cybersecurity researchers, according to Socket.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Saudi Arabia's Vision 2030 Encounters Houthi Challenges Amidst Growth in Trade and Technology

- Saudi Arabia strengthens regional trade ties with Egypt, aiming to boost 86% of Egyptian firms' trade under Vision 2030, focusing on tech and energy sectors. - Chinese aesthetic tech firm Aphranel showcases innovations at Saudi medical congress, highlighting growing Middle East market integration. - Houthi threats in Yemen persist, raising regional security risks that could hinder Saudi economic ambitions and foreign investment goals. - Saudi-Egyptian investment agreements aim to enhance legal frameworks

Bitget-RWA2025/11/30 16:44
Saudi Arabia's Vision 2030 Encounters Houthi Challenges Amidst Growth in Trade and Technology

"Retail's Digital Revolution: Black Friday's 9.1% Online Spike Signals New Consumer Era" <div>Retail's Digital Revolution: Black Friday's 9.1% Online Spike Signals New Consumer Era</div> 改写: <div>The Digital Shift in Retail: Black Friday Sees 9.1% Surge in Online Sales, Marking a New Age for Shoppers</div>

- U.S. online Black Friday spending hit $11.8B in 2025, a 9.1% surge driven by AI tools and social media campaigns. - In-store traffic fell 3.6% as shoppers spread purchases across extended promotions, while tariffs pushed average prices up 7% despite 1% lower order volumes. - Holiday sales are projected to reach $1.01-$1.02 trillion, reflecting a 3.7-4.2% growth but slower than 2023's 4.3% increase. - Scams targeted 31% of U.S. adults, while grassroots boycotts against Trump-linked retailers emerged, thou

Bitget-RWA2025/11/30 16:44
"Retail's Digital Revolution: Black Friday's 9.1% Online Spike Signals New Consumer Era"

<div>Retail's Digital Revolution: Black Friday's 9.1% Online Spike Signals New Consumer Era</div>

改写:

<div>The Digital Shift in Retail: Black Friday Sees 9.1% Surge in Online Sales, Marking a New Age for Shoppers</div>

Bitcoin News Today: Surging Institutional Interest Pushes BlackRock’s Bitcoin ETF to $70 Billion

- BlackRock's IBIT bitcoin ETF surged to $70.7B in 341 days, generating $245M annual fees as top revenue driver. - U.S. spot bitcoin ETF approval fueled institutional demand, with IBIT capturing 3% of total bitcoin supply. - BlackRock increased its own IBIT stake by 14%, despite $2.34B November outflows deemed "normal" for retail-driven products. - ETF resilience shown through $21.1M November 27 inflow, reinforcing bitcoin's strategic role amid macroeconomic uncertainties.

Bitget-RWA2025/11/30 16:44

Hyperliquid News Today: Hayes-Hon Dispute Highlights the Rift Between Crypto Fundamentals and Market Hype

- Monad's MON token collapsed 40% in three days, triggering $6M+ liquidations on HyperLiquid as high-FDV projects face volatility risks. - Arthur Hayes criticized MON's 90% locked supply as a "hot potato" scheme, while founder Keone Hon defended its C++/Rust architecture and 1-second finality. - Whale wallets lost $1.9M-$4.17M in leveraged positions, highlighting systemic risks in low-liquidity tokens amid spoofed transfers and declining trading volume. - The debate underscores crypto's infrastructure vs.

Bitget-RWA2025/11/30 16:28
Hyperliquid News Today: Hayes-Hon Dispute Highlights the Rift Between Crypto Fundamentals and Market Hype