Trade Haven Hub - Investing and Stock News
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
  • Investment Tips
  • Trade Tips
  • Crypto News
  • Economy News
  • Stock Market
No Result
View All Result
Trade Haven Hub - Investing and Stock News
No Result
View All Result
Home Crypto News

Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap

by
November 27, 2025
in Crypto News
0
Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

A newly discovered malicious Chrome extension is stealing funds from Solana traders by quietly siphoning a fee from every swap they execute, according to new findings from Socket’s Threat Research Team.

The extension, called Crypto Copilot, has been available on the Chrome Web Store since June 2024 and markets itself as a shortcut for executing Solana trades directly from users’ X feeds.

Behind the interface, however, researchers found code designed to insert an additional transfer into each Raydium swap, diverting at least 0.0013 SOL, or 0.05% of each transaction, to an attacker-controlled wallet.

Source: Socket

Crypto Copilot Sends Wallet Data to Suspicious Backend While Draining Trader Funds

Socket researchers say the extension constructs a normal Raydium swap instruction but then appends a second instruction that transfers SOL to the wallet address Bjeida.

Users only see the legitimate swap in the interface, and most wallet confirmation windows display only a high-level summary of the transaction rather than the full list of instructions.

As a result, traders approve what appears to be a standard transaction, unaware of the hidden transfer embedded inside it.

The fee logic is fully hardcoded inside the extension and buried under layers of obfuscated JavaScript.

Socket notes that the extension applies whichever is greater between the minimum fee and the percentage-based fee, meaning trades above 2.6 SOL incur the full 0.05% extraction.

Researchers found that the extension uses variable renaming and aggressive minification to conceal the behavior, and the attacker’s wallet is labeled under an innocuous variable deep inside the bundle.

The extension remains online at the time of reporting. Socket says it has submitted a takedown request to Google, but has not received confirmation that action has been taken.

Beyond the fee theft, investigators also discovered that Crypto Copilot connects to a backend hosted on crypto-coplilot-dashboard.vercel.app, a misspelled domain that shows only a blank placeholder page.

Source: Socket

Despite the empty site, the extension regularly sends connected wallet identifiers and activity data to this backend, along with using a hardcoded Helius API key for transaction simulation and RPC calls.

A separate domain tied to the tool, cryptocopilot.app, is currently parked.

Researchers say the absence of documentation, a functioning dashboard, or any supporting infrastructure is inconsistent with a legitimate trading product and instead reflects common practices seen in malicious browser extensions.

While on-chain activity linked to the attacker’s wallet remains limited, investigators believe the low transaction volume likely reflects the extension’s relatively small distribution rather than an absence of risk.

They warn that the mechanism scales with trading activity, meaning high-volume users could lose larger amounts over time without noticing the incremental drain.

Crypto Losses Fall to 2025 Lows, but Browser Extension Attacks Continue to Climb

The discovery comes during a period of heightened scrutiny around browser-based crypto threats. In July, more than 40 malicious Firefox extensions were found impersonating major wallet providers, including MetaMask, Coinbase, Phantom, OKX, and Trust Wallet.

Koi Security exposes 40+ malicious crypto wallet extensions in Firefox store targeting seed phrases from @coinbase, @MetaMask, and @TrustWallet as crypto losses explode to $2.2B in 2025.#CryptoWallet #Hackhttps://t.co/0EcvDev8SY

— Cryptonews.com (@cryptonews) July 3, 2025

Those extensions harvested wallet credentials directly from users’ browsers and transmitted them to attacker-controlled servers.

Exchanges such as OKX publicly warned users and filed complaints after discovering fake plugins masquerading as official wallet tools. Browser extensions have emerged as one of the most persistent attack vectors in 2025, contributing to a growing share of crypto losses.

Wallet-related breaches accounted for $1.7 billion of the $2.2 billion stolen across the first half of the year, according to CertiK. Phishing incidents added another $410 million.

Despite the rise in extension-based threats, the broader crypto sector briefly experienced a decline in successful hacks.

PeckShield recorded just $18.18 million stolen across 15 incidents in October, the lowest monthly total of the year.

Crypto exploits plunged 22% in September, but losses still totaled $127M. The largest attacks hit $UXLINK ($44M) and @swissborg ($41.5M), according to data from @PeckShieldAlert. #crypto #DeFi #hackshttps://t.co/FsrFl0qJaw

— Cryptonews.com (@cryptonews) October 2, 2025

That figure had been far higher a month earlier when losses reached $127.06 million in September, driven by nearly 20 major exploits. But even as overall losses dipped, high-profile breaches continued.

The post Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap appeared first on Cryptonews.

Previous Post

NextSource Materials Hosts Strategic Investors in Abu Dhabi for Site Visit of Battery Anode Facility

Next Post

BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

Next Post
BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

  • Trending
  • Comments
  • Latest
Buy Bitcoin Under $100K Before The Next Bull Run

Buy Bitcoin Under $100K Before The Next Bull Run

April 22, 2025
Zeldin, McCain hammer Crockett on Epstein donations claim

Zeldin, McCain hammer Crockett on Epstein donations claim

November 20, 2025
Best Altcoin Coin to Buy During the Crypto Crash – 21 November

Best Altcoin Coin to Buy During the Crypto Crash – 21 November

November 22, 2025
Target is eliminating 1,800 corporate jobs as it looks to reclaim its lost luster

Target is eliminating 1,800 corporate jobs as it looks to reclaim its lost luster

October 24, 2025
Bitcoin Above $91K Eases Stress – But Depth, Flows and Stablecoins Still Call the Shots

Bitcoin Above $91K Eases Stress – But Depth, Flows and Stablecoins Still Call the Shots

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Quantum Computing: its Evolution and its Potential Future

Quantum Computing: its Evolution and its Potential Future

0
Air Direct Capture – Reducing CO2 from the Atmosphere

Air Direct Capture – Reducing CO2 from the Atmosphere

0
Bitcoin Above $91K Eases Stress – But Depth, Flows and Stablecoins Still Call the Shots

Bitcoin Above $91K Eases Stress – But Depth, Flows and Stablecoins Still Call the Shots

November 27, 2025
BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

November 27, 2025
Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap

Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap

November 27, 2025
NextSource Materials Hosts Strategic Investors in Abu Dhabi for Site Visit of Battery Anode Facility

NextSource Materials Hosts Strategic Investors in Abu Dhabi for Site Visit of Battery Anode Facility

November 27, 2025

    Stay updated with the latest news, exclusive offers, and special promotions. Sign up now and be the first to know! As a member, you'll receive curated content, insider tips, and invitations to exclusive events. Don't miss out on being part of something special.


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent News

    Bitcoin Above $91K Eases Stress – But Depth, Flows and Stablecoins Still Call the Shots

    Bitcoin Above $91K Eases Stress – But Depth, Flows and Stablecoins Still Call the Shots

    November 27, 2025
    BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

    BTC Price Prediction: Bitcoin Reclaims $90,000 as Kalshi Traders Put 60% Odds on $100K by Year-End

    November 27, 2025
    Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap

    Warning: New Chrome Extension Drains Solana Traders – 0.05% Stolen Per Swap

    November 27, 2025
    NextSource Materials Hosts Strategic Investors in Abu Dhabi for Site Visit of Battery Anode Facility

    NextSource Materials Hosts Strategic Investors in Abu Dhabi for Site Visit of Battery Anode Facility

    November 27, 2025
    • About us
    • Contact us
    • Privacy Policy
    • Terms & Conditions

    Copyright © 2025 tradehavenhub.com | All Rights Reserved

    No Result
    View All Result
    • Investment Tips
    • Trade Tips
    • Crypto News
    • Economy News
    • Stock Market

    Copyright © 2025 tradehavenhub.com | All Rights Reserved