DeFi Daily News
Monday, March 30, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home DeFi Web 3

rewrite this title Malware Chrome Extension Secretly Siphoned Fees From Solana Traders for Months – Decrypt

Vismaya V by Vismaya V
November 27, 2025
in Web 3
0 0
0
rewrite this title Malware Chrome Extension Secretly Siphoned Fees From Solana Traders for Months – Decrypt
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags In brief
Chrome extension Crypto Copilot secretly adds a hidden SOL transfer to every Raydium swap, siphoning fees to an attacker’s wallet.
Security platform Socket found the extension uses obfuscated code and a misspelled, inactive backend domain to mask its activity.
On-chain theft remains small so far, but the mechanism scales with trade size, and the extension is still live on the Chrome Web Store.
A Chrome extension marketed as a convenient trading tool has been secretly siphoning SOL from users’ swaps since last June, injecting hidden fees into every transaction while masquerading as a legitimate Solana trading assistant.Cybersecurity firm Socket discovered malware extension Crypto Copilot during “continuous monitoring” of the Chrome Web Store, security engineer and researcher Kush Pandya told Decrypt.
🚨 Socket researchers uncovered a malicious Chrome extension that injects hidden #SOL transfers into Raydium swaps, quietly siphoning fees to an attacker wallet.
Full analysis → https://t.co/bdGOXViJpA #Solana
— Socket (@SocketSecurity) November 25, 2025In an analysis of the malicious extension published Wednesday, Pandya wrote that Crypto Copilot quietly appends an extra transfer instruction to every Solana swap, extracting a minimum of 0.0013 SOL or 0.05% of the trade amount to an attacker-controlled wallet.“Our AI scanner flagged multiple indicators: aggressive code obfuscation, a hardcoded Solana address embedded in transaction logic, and discrepancies between the extension’s stated functionality and actual network behavior,” Pandya told Decrypt, adding that “These alerts triggered deeper manual analysis that confirmed the hidden fee extraction mechanism.”The research points to risks in browser-based crypto tools, particularly extensions that combine social media integration with transaction signing capabilities.The extension has remained available on the Chrome Web Store for months, with no warning to users about the undisclosed fees buried in heavily obfuscated code, the report says.”The fee behavior is never disclosed on the Chrome Web Store listing, and the logic implementing it is buried inside heavily obfuscated code,” Pandya noted.Each time a user swaps tokens, the extension generates the proper Raydium swap instruction but discreetly tacks on an extra transfer directing SOL to the attacker’s address.Raydium is a Solana-based decentralized exchange and automated market maker, whereas a “Raydium swap” simply refers to exchanging one token for another through its liquidity pools.Users who installed Crypto Copilot, believing it would streamline their Solana trading, have unknowingly been paying hidden fees with every swap, fees that never appeared in the extension’s marketing materials or Chrome Web Store listing.The interface shows only the swap details, and wallet pop-ups summarize the transaction, so users sign what looks like a single swap even though both instructions execute simultaneously on-chain.The attacker’s wallet has received only small amounts to date, a sign that Crypto Copilot hasn’t reached many users yet, rather than an indication that the exploit is low-risk, as per the report.The fee mechanism scales with trade size, as for swaps under 2.6 SOL, the minimum 0.0013 SOL fee applies, and above that threshold, the 0.05% percentage fee takes effect, meaning a 100 SOL swap would extract 0.05 SOL, roughly $10 at current prices.The extension’s main domain cryptocopilot[.]app is parked by domain registry GoDaddy, while the backend at crypto-coplilot-dashboard[.]vercel[.]app, notably misspelled, displays only a blank placeholder page despite collecting wallet data, the report says.Socket has submitted a takedown request to Google’s Chrome Web Store security team, though the extension remained available at the time of publication.The platform has urged users to review each instruction before signing transactions, avoid closed-source trading extensions requesting signing permissions, and migrate assets to clean wallets if they installed Crypto Copilot.Malware patternsMalware remains a growing concern for crypto users. In September, a malware strain called ModStealer was found targeting crypto wallets across Windows, Linux, and macOS through fake job recruiter ads, evading detection by major antivirus engines for almost a month.Ledger CTO Charles Guillemet has previously warned that attackers had compromised an NPM developer account, with malicious code attempting to silently swap crypto wallet addresses during transactions across multiple blockchains.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more. and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: ChromeDecryptextensionfeesmalwareMonthsrewriteSecretlySiphonedSolanatitleTraders
ShareTweetShare
Previous Post

rewrite this title with good SEO XRP Price To $10, Solana To $600, And Dogecoin At $0.75? Analyst Reveals When | Bitcoinist.com

Next Post

rewrite this title Solana tokens rip on Upbit after $32M hack due to halted arbitrage

Next Post
rewrite this title Solana tokens rip on Upbit after M hack due to halted arbitrage

rewrite this title Solana tokens rip on Upbit after $32M hack due to halted arbitrage

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

rewrite this title Google Unveils Flow: An All-in-One AI Video Editing Tool That Can Do It All!

May 21, 2025
rewrite this title How to Get Top Solana Token Holders – Moralis APIs

rewrite this title How to Get Top Solana Token Holders – Moralis APIs

May 14, 2025
rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

rewrite this title and make it good for SEO Hyperliquid Deep Dive: Understand HYPE and HLP Model

April 3, 2025
Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

Vance, Trump’s VP Choice, Advocates for Stringent China Policy: Analyst Insights – Reuters

July 16, 2024
Vitalik Receives Criticism for Underestimating DeFi’s Contribution to Ethereum’s Expansion

Vitalik Receives Criticism for Underestimating DeFi’s Contribution to Ethereum’s Expansion

August 26, 2024
rewrite this title Hannah Kobayashi’s Family Reacts After Police Say She Voluntarily Crossed Border to Mexico

rewrite this title Hannah Kobayashi’s Family Reacts After Police Say She Voluntarily Crossed Border to Mexico

December 3, 2024
rewrite this title Bitcoin Breakdown Confirmed: Bearish Continuation Looms Despite Short-Term Bounce Setup

rewrite this title Bitcoin Breakdown Confirmed: Bearish Continuation Looms Despite Short-Term Bounce Setup

March 28, 2026
rewrite this title “I was just hanging on”: Michael McDowell admits he needed more than talent to stay afloat in NASCAR

rewrite this title “I was just hanging on”: Michael McDowell admits he needed more than talent to stay afloat in NASCAR

March 28, 2026
rewrite this title ‘Malcolm In The Middle’ Team On The Possibility Of A Full-Fledged Reboot: “A Whole New Set Of Characters And Circumstances That Are Ripe”

rewrite this title ‘Malcolm In The Middle’ Team On The Possibility Of A Full-Fledged Reboot: “A Whole New Set Of Characters And Circumstances That Are Ripe”

March 28, 2026
rewrite this title Today's NYT Strands Hints, Answer and Help for March 29 #756 – CNET

rewrite this title Today's NYT Strands Hints, Answer and Help for March 29 #756 – CNET

March 28, 2026
rewrite this title Arsenal Women 5-2 Tottenham Women: Alessia Russo hat-trick keeps Gunners in Women’s Super League title fight

rewrite this title Arsenal Women 5-2 Tottenham Women: Alessia Russo hat-trick keeps Gunners in Women’s Super League title fight

March 28, 2026
He Messed Up Bad, Now His Wife Doesn’t Trust Him

He Messed Up Bad, Now His Wife Doesn’t Trust Him

March 28, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.