Scan to download
BTC $60,376.45 -3.39%
ETH $1,544.04 -7.90%
BNB $572.21 -3.17%
XRP $1.07 -5.42%
SOL $61.42 -7.48%
TRX $0.3185 -2.19%
DOGE $0.0801 -5.31%
ADA $0.1542 -6.45%
BCH $218.44 -4.70%
LINK $7.23 -5.02%
HYPE $58.48 -4.75%
AAVE $60.30 -10.48%
SUI $0.6895 -3.77%
XLM $0.1949 +1.51%
ZEC $365.83 +9.78%
BTC $60,376.45 -3.39%
ETH $1,544.04 -7.90%
BNB $572.21 -3.17%
XRP $1.07 -5.42%
SOL $61.42 -7.48%
TRX $0.3185 -2.19%
DOGE $0.0801 -5.31%
ADA $0.1542 -6.45%
BCH $218.44 -4.70%
LINK $7.23 -5.02%
HYPE $58.48 -4.75%
AAVE $60.30 -10.48%
SUI $0.6895 -3.77%
XLM $0.1949 +1.51%
ZEC $365.83 +9.78%

Malicious Chrome extensions secretly steal Solana transaction funds

2025-11-27 22:14:49
Collection

According to Cointelegraph, cybersecurity company Socket has discovered a malicious Chrome extension called "Crypto Copilot" that is secretly stealing funds from users' Solana transactions.

The extension allows users to conduct Solana transactions directly from the X social media platform, but it injects additional instructions into each transaction, siphoning off at least 0.0013 SOL or 0.05% of the transaction amount. Unlike typical wallet-draining malware, Crypto Copilot executes transactions using the Raydium decentralized exchange while adding a second instruction to transfer SOL to the attacker's wallet, with the user interface only displaying a transaction summary, hiding the separate operational instructions. Since its release on June 18, 2024, the extension currently has only 15 users. Socket has submitted a takedown request to the Chrome Web Store security team. Security experts warn users that the Chrome extension ecosystem has long been a popular target for cryptocurrency scams due to its large user base and scalable design.

app_icon
ChainCatcher Building the Web3 world with innovations.