The post Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades appeared on BitcoinEthereumNews.com. Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks. Summary Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​ Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​ Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification. A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team. The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address. Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated. The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said. A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms. Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users… The post Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades appeared on BitcoinEthereumNews.com. Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks. Summary Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​ Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​ Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification. A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team. The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address. Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated. The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said. A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms. Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users…

Solana browser extension ‘Crypto Copilot’ exposed for diverting user funds in secret trades

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Chrome Solana extension ‘Crypto Copilot’ covertly diverts user funds in swaps, highlighting browser crypto security risks.

Summary

  • Crypto Copilot Chrome extension embeds hidden transfer instructions in Solana swap transactions.​
  • Cybersecurity firm Socket uncovered secret fund diversions to attacker’s wallet via concealed commands.​
  • Incident highlights browser-based crypto tool vulnerabilities and need for user transaction verification.

A Chrome browser extension designed for Solana cryptocurrency trading secretly diverts funds from users by embedding hidden transfer instructions in swap transactions, according to a report from cybersecurity firm Socket’s Threat Research Team.

The extension, named Crypto Copilot, enables users to trade SOL (SOL) tokens directly from X, formerly known as Twitter, while covertly redirecting a portion of each transaction to an attacker-controlled wallet, Socket reported. Each swap executed through the extension includes a concealed instruction transferring 0.05 percent of the transaction value, or a minimum of 0.0013 SOL, to a hardcoded wallet address.

Published on the Chrome Web Store in mid-2024, Crypto Copilot markets itself as a tool for instant Solana trading, according to the report. Users view only the primary swap transaction on confirmation screens, which summarize the transaction without disclosing the additional transfer instruction, Socket stated.

The extension employs obfuscation techniques including code minification and variable renaming to conceal the malicious behavior, according to the cybersecurity firm. The software communicates with a backend server hosted at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, tracks user activity, and reports referral data, the report said.

A second domain associated with the extension, cryptocopilot.app, remains parked and non-functional. Socket noted that the absence of an operational dashboard is inconsistent with legitimate trading platforms.

Crypto Copilot utilizes Raydium, an automated market maker on the Solana blockchain, to execute swaps. The extension appends a hidden SystemProgram.transfer instruction to each trade, completing atomic on-chain transfers that divert funds while users approve what appears to be a single transaction, according to the report.

Solana browser extension Crypto Copilot studied by Socket

Although installation numbers remain low, Socket warned that cumulative losses pose significant risks for frequent traders. Incremental fund diversions may accumulate undetected, illustrating broader security threats posed by browser-based cryptocurrency tools, the firm stated.

Previous incidents have involved malicious Chrome and Firefox extensions targeting cryptocurrency wallets including MetaMask, Phantom, and Coinbase, according to industry reports.

The incident highlights vulnerabilities in browser-based cryptocurrency security and the importance of transaction verification before approval, Socket stated. As browser-based tools increasingly integrate cryptocurrency trading functionality, enhanced monitoring and oversight of Chrome’s extension ecosystem may be necessary to protect decentralized finance users, the report concluded.

Solana traders are advised to verify extension legitimacy, review transaction instructions in detail, and monitor updates from cybersecurity researchers, according to Socket.

Source: https://crypto.news/solana-browser-extension-crypto-copilot-exposed-for-diverting-user-funds-in-secret-trades/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ripple Cryptocurrency News: XRP Tundra Presale Launches with Dual-Token Model

Ripple Cryptocurrency News: XRP Tundra Presale Launches with Dual-Token Model

The post Ripple Cryptocurrency News: XRP Tundra Presale Launches with Dual-Token Model appeared on BitcoinEthereumNews.com. The latest development in the XRP ecosystem is not about the ongoing legal debates or Ripple’s expansion in cross-border payments. Instead, focus has shifted to a new presale initiative that is drawing attention across the digital asset community. XRP Tundra has launched with a dual-token model designed to give early participants both utility and governance advantages. It also links directly to upcoming staking opportunities. This approach comes when many XRP holders are searching for additional yield opportunities outside the standard XRPL ecosystem. With the introduction of Cryo Vaults and Frost Keys, the project intends to enable staking of XRP itself. It could generate potential returns of up to 30% APY. While staking has not yet gone live, presale participants secure the right to join from day one. That establishes a pathway that blends presale value with practical utility. Two Tokens for Price of One The presale currently runs at a fixed $0.01 entry point. For that price, participants receive two separate tokens: TUNDRA-S, issued on Solana and designed for utility and yield, and TUNDRA-X, issued on XRPL for governance and reserve purposes. This approach links Solana’s high-performance smart contract ecosystem with the XRP Ledger’s settlement and liquidity infrastructure. Forty percent of the project’s total supply is for the presale. Later phases will see the price adjust upward. It will reward early adopters with both immediate value and long-term positioning in the ecosystem. For many investors, the appeal lies not just in acquiring discounted tokens. It is also on the guaranteed path to XRP staking once Cryo Vaults and Frost Keys go live. Staking Model: Cryo Vaults and Frost Keys XRP Tundra’s staking framework can offer competitive returns compared to traditional financial instruments and other blockchain validators. Through Cryo Vaults, participants will be able to lock their XRP, generating Frost Keys…
Share
BitcoinEthereumNews2025/09/18 19:41
Stabull’s Expansive Role in the DeFi Ecosystem

Stabull’s Expansive Role in the DeFi Ecosystem

The post Stabull’s Expansive Role in the DeFi Ecosystem appeared on BitcoinEthereumNews.com. A detailed examination of the Stabull protocol reveals its reach extends
Share
BitcoinEthereumNews2026/03/24 07:28
Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

The post Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says appeared on BitcoinEthereumNews.com. Crypto industry insiders
Share
BitcoinEthereumNews2026/03/24 06:58