The post Solana Users Face Hidden SOL Fees from Malicious Chrome Extension appeared on BitcoinEthereumNews.com. Crypto Copilot malware has been secretly draining SOL from users’ wallets since June 2025 by injecting hidden transfer instructions into Raydium swaps. Cybersecurity firm Socket uncovered this threat, revealing how the Chrome extension extracts at least 0.0013 SOL or 0.05% per trade without user knowledge. Immediate removal and transaction vigilance are essential to protect Solana assets. Cybersecurity researchers at Socket identified the malicious extension during routine Chrome Web Store monitoring. The extension appends undisclosed SOL transfers to every swap, scaling fees based on trade size for maximum extraction. Over 0.0013 SOL minimum or 0.05% of larger trades have been siphoned, with total funds to date remaining modest due to limited adoption. What is the Crypto Copilot Malware? The Crypto Copilot malware is a deceptive Chrome browser extension posing as a Solana trading assistant that has been active since June 2025. It injects hidden transaction instructions into Raydium swaps, silently transferring SOL to an attacker-controlled wallet. Users remain unaware as the interface masks the extra fee, emphasizing the need for caution with third-party trading tools. How Does Solana Hidden Fees Work in This Extension? Solana hidden fees in the Crypto Copilot extension operate through obfuscated code that appends a secondary transfer to legitimate swap instructions on Raydium, a leading Solana decentralized exchange. For trades under 2.6 SOL, a flat 0.0013 SOL fee applies; larger swaps incur 0.05% of the amount, potentially costing $10 on a 100 SOL trade at current prices. Security engineer Kush Pandya from Socket explained, “Aggressive code obfuscation and hardcoded attacker addresses were key red flags our AI scanner detected, leading to confirmation of the fee mechanism.” This structure evades user detection, as wallet pop-ups show only the primary swap details, while both instructions execute on-chain simultaneously. The report highlights that such browser extensions combining social features with… The post Solana Users Face Hidden SOL Fees from Malicious Chrome Extension appeared on BitcoinEthereumNews.com. Crypto Copilot malware has been secretly draining SOL from users’ wallets since June 2025 by injecting hidden transfer instructions into Raydium swaps. Cybersecurity firm Socket uncovered this threat, revealing how the Chrome extension extracts at least 0.0013 SOL or 0.05% per trade without user knowledge. Immediate removal and transaction vigilance are essential to protect Solana assets. Cybersecurity researchers at Socket identified the malicious extension during routine Chrome Web Store monitoring. The extension appends undisclosed SOL transfers to every swap, scaling fees based on trade size for maximum extraction. Over 0.0013 SOL minimum or 0.05% of larger trades have been siphoned, with total funds to date remaining modest due to limited adoption. What is the Crypto Copilot Malware? The Crypto Copilot malware is a deceptive Chrome browser extension posing as a Solana trading assistant that has been active since June 2025. It injects hidden transaction instructions into Raydium swaps, silently transferring SOL to an attacker-controlled wallet. Users remain unaware as the interface masks the extra fee, emphasizing the need for caution with third-party trading tools. How Does Solana Hidden Fees Work in This Extension? Solana hidden fees in the Crypto Copilot extension operate through obfuscated code that appends a secondary transfer to legitimate swap instructions on Raydium, a leading Solana decentralized exchange. For trades under 2.6 SOL, a flat 0.0013 SOL fee applies; larger swaps incur 0.05% of the amount, potentially costing $10 on a 100 SOL trade at current prices. Security engineer Kush Pandya from Socket explained, “Aggressive code obfuscation and hardcoded attacker addresses were key red flags our AI scanner detected, leading to confirmation of the fee mechanism.” This structure evades user detection, as wallet pop-ups show only the primary swap details, while both instructions execute on-chain simultaneously. The report highlights that such browser extensions combining social features with…

Solana Users Face Hidden SOL Fees from Malicious Chrome Extension

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto Copilot malware has been secretly draining SOL from users’ wallets since June 2025 by injecting hidden transfer instructions into Raydium swaps. Cybersecurity firm Socket uncovered this threat, revealing how the Chrome extension extracts at least 0.0013 SOL or 0.05% per trade without user knowledge. Immediate removal and transaction vigilance are essential to protect Solana assets.

  • Cybersecurity researchers at Socket identified the malicious extension during routine Chrome Web Store monitoring.
  • The extension appends undisclosed SOL transfers to every swap, scaling fees based on trade size for maximum extraction.
  • Over 0.0013 SOL minimum or 0.05% of larger trades have been siphoned, with total funds to date remaining modest due to limited adoption.

What is the Crypto Copilot Malware?

The Crypto Copilot malware is a deceptive Chrome browser extension posing as a Solana trading assistant that has been active since June 2025. It injects hidden transaction instructions into Raydium swaps, silently transferring SOL to an attacker-controlled wallet. Users remain unaware as the interface masks the extra fee, emphasizing the need for caution with third-party trading tools.

How Does Solana Hidden Fees Work in This Extension?

Solana hidden fees in the Crypto Copilot extension operate through obfuscated code that appends a secondary transfer to legitimate swap instructions on Raydium, a leading Solana decentralized exchange. For trades under 2.6 SOL, a flat 0.0013 SOL fee applies; larger swaps incur 0.05% of the amount, potentially costing $10 on a 100 SOL trade at current prices. Security engineer Kush Pandya from Socket explained, “Aggressive code obfuscation and hardcoded attacker addresses were key red flags our AI scanner detected, leading to confirmation of the fee mechanism.” This structure evades user detection, as wallet pop-ups show only the primary swap details, while both instructions execute on-chain simultaneously. The report highlights that such browser extensions combining social features with signing permissions amplify risks, with the extension’s domain parked and backend showing suspicious placeholders.

Frequently Asked Questions

How Can I Tell If I’ve Installed the Crypto Copilot Extension?

Check your Chrome extensions list for “Crypto Copilot” and verify its ID against known malicious reports from Socket’s analysis. If installed since June 2025 and used for Raydium swaps, review your Solana wallet transaction history for unexplained small SOL outflows to unfamiliar addresses. Uninstall immediately and scan your device to prevent further exposure.

What Should Solana Users Do to Avoid Hidden Swap Fees?

To dodge hidden swap fees on Solana, always inspect transaction details before signing, especially with browser extensions. Stick to verified, open-source tools and avoid those requesting broad wallet permissions. If compromised, transfer assets to a new wallet and enable multi-factor authentication for enhanced security against evolving malware threats.

Key Takeaways

  • Malicious Extensions Pose Real Risks: Crypto Copilot demonstrates how seemingly helpful tools can embed hidden SOL transfers, underscoring the dangers of unvetted browser add-ons in crypto trading.
  • Early Detection Saved Potential Losses: Socket’s AI monitoring flagged obfuscated code and discrepancies, limiting the attacker’s haul to small amounts despite months of operation.
  • Proactive Steps for Users: Regularly audit extensions, review on-chain transactions, and migrate to secure wallets to mitigate similar Solana threats moving forward.

Conclusion

The discovery of the Crypto Copilot malware highlights ongoing vulnerabilities in Solana trading tools, where hidden fees can erode user funds without detection. As cybersecurity firms like Socket continue to expose such threats through diligent monitoring, crypto enthusiasts must prioritize transaction verification and tool vetting. Stay informed and adopt secure practices to navigate the evolving landscape of digital asset security with confidence.

Word count: 728

Source: https://en.coinotag.com/solana-users-face-hidden-sol-fees-from-malicious-chrome-extension

Market Opportunity
Solana Logo
Solana Price(SOL)
$89.14
$89.14$89.14
-0.69%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Siren Token Sheds 70% as Analysts Question Supply Structure

Siren Token Sheds 70% as Analysts Question Supply Structure

The post Siren Token Sheds 70% as Analysts Question Supply Structure appeared on BitcoinEthereumNews.com. The Siren (SIREN) token plunged nearly 70% on Tuesday,
Share
BitcoinEthereumNews2026/03/25 01:00
Record instroom Bitcoin-ETF’s – richting $120.000?

Record instroom Bitcoin-ETF’s – richting $120.000?

Connect met Like-minded Crypto Enthusiasts! Connect op Discord! Check onze Discord   De markt voor Bitcoin ETF’s laat wederom een opvallende trend zien. De afgelopen week werd de grootste instroom sinds juli geregistreerd, een ontwikkeling die de aandacht van zowel institutionele als particuliere beleggers trekt. Deze instroom zorgt voor nieuwe speculatie over de vraag of Bitcoin binnenkort de grens van 120.000 dollar kan doorbreken. Laten we dit hieronder nader bekijken. Grootste instroom sinds juli Volgens recente marktgegevens wist de Amerikaanse spot Bitcoin ETF’s een instroom te krijgen ver boven de gemiddelde niveaus van de afgelopen weken. Alleen al op 16 september werd meer dan 290 miljoen dollar netto in deze fondsen gestort. Daarmee markeert dit de zevende opeenvolgende dag met positieve instroom, een duidelijk teken dat institutionele belangstelling opnieuw toeneemt. De grootste bijdrage kwam van BlackRock’s iShares Bitcoin Trust, dat meer dan 200 miljoen dollar stortte. Ook de ETF’s van Fidelity en Ark lieten grote instroom zien. Kortom, de instroom blijft positief. U.S. spot Bitcoin ETFs Ignite with a $553M daily inflow, pushing a four-day streak to $1.7B. Ether ETFs also saw a resurgence with $113M in new funds. #Bitcoin #ETF #ETHhttps://t.co/zZiNqtKSEm — Cryptonews.com (@cryptonews) September 12, 2025 Hoe instroom prijsondersteuning biedt De sterke instroom in Bitcoin ETF’s is meer dan een mijlpaal. Het laat zien hoe de vraag naar Bitcoin groeit vanuit institutionele hoek en dat deze vraag niet voor een keer is, maar structureel is. Omdat de instroom de hoeveelheid nieuw geminde Bitcoin overtreft, ontstaat er een overschot qua vraag dat de prijs positief kan beïnvloeden. Dit verschil tussen aanbod en vraag zorgt ervoor dat het dalende risico wordt beperkt. Wanneer institutionele beleggers via ETF’s posities opbouwen, gebeurt dit bovendien vaak met een langere beleggingshorizon. Dat geeft de markt extra stabiliteit, zeker in een periode waarin onzekerheden rondom rente en macro-economie nog altijd spelen. Signaalfunctie voor beleggers Voor beleggers in de crypto markt hebben deze cijfers een signaalfunctie. Het vertrouwen dat grote institutionele spelers door miljarden te alloceren in gereguleerde beleggingsproducten bevestigt dat Bitcoin steeds meer gekocht wordt in de traditionele financiële wereld. Dit momentum werkt vaak door naar de bredere markt, omdat particuliere beleggers dit zien als bevestiging dat de trend omhoog sterker wordt. Ook technische analyse wijst op een belangrijke fase. De koers van Bitcoin beweegt rond de 118.000 dollar, een weerstandsniveau dat al meerdere keren is getest. Het momentum dat voortkomt uit de ETF instroom kan de kracht geven om dit niveau te doorbreken en een nieuwe fase van prijsstijging richting 120.000 dollar in te luiden. Op korte termijn richting de $120.000? Hoewel niemand met zekerheid kan voorspellen of Bitcoin dit niveau direct zal bereiken, biedt de huidige context sterke aanwijzingen dat de kans aanwezig is. De combinatie van record instroom, institutioneel vertrouwen en een gunstig technisch analyse vormt een krachtige mix. Beleggers doen er goed aan om rekening te houden met de invloed van externe factoren zoals beleidsbesluiten van de Federal Reserve. Best wallet - betrouwbare en anonieme wallet Best wallet - betrouwbare en anonieme wallet Meer dan 60 chains beschikbaar voor alle crypto Vroege toegang tot nieuwe projecten Hoge staking belongingen Lage transactiekosten Best wallet review Koop nu via Best Wallet Let op: cryptocurrency is een zeer volatiele en ongereguleerde investering. Doe je eigen onderzoek.   Het bericht Record instroom Bitcoin-ETF’s – richting $120.000? is geschreven door Timo Bruinsel en verscheen als eerst op Bitcoinmagazine.nl.
Share
Coinstats2025/09/18 01:31
Turkey’s Cryptocurrency Taxation Bill Postponed Until Tomorrow

Turkey’s Cryptocurrency Taxation Bill Postponed Until Tomorrow

According to breaking news, the bill, which also determines the critical cryptocurrency taxation process, has been postponed until tomorrow in the Turkish Grand
Share
Bitcoinsistemi2026/03/25 00:56