A Deceptive Chrome Add-On Exposes a New Attack Vector for Solana Traders
A fake Solana trading extension injects hidden transfer fees, revealing a growing threat to Web3 users.
A seemingly harmless browser extension posing as a Solana trading assistant has revealed how easily malicious actors can exploit user trust within the Web3 ecosystem. The Chrome add-on, known as Crypto Copilot, was marketed as a lightweight tool that allowed people to monitor token activity and execute swaps directly from social media feeds. In practice, it was designed to quietly skim funds from every transaction, turning routine swaps into a revenue stream for the attackers.
Security analysts uncovered that the extension inserted unauthorized instructions into legitimate Raydium swap payloads. While the front-end displayed normal functionality—price feeds, wallet connections, trading shortcuts—the extension manipulated the underlying structure of each transaction. It would generate the correct Raydium instruction but then append a separate, hidden transfer sending a fraction of SOL to a wallet controlled by the attacker. The siphoned amount was either a fixed 0.0013 SOL for small trades or 0.05 percent of the transaction for larger swaps, creating a mechanism that could scale quietly with user activity.
One factor that made this attack effective is how wallets typically present transaction previews. Most users see a simplified summary rather than the full list of embedded instructions. Unless someone manually expands the detailed view, they will not notice that they are authorizing two distinct actions. This dynamic illustrates a broader challenge in decentralized finance: security tools have become more sophisticated, but user interfaces often obscure the technical layers where threats hide.
Crypto Copilot was first identified by Socket’s Threat Research Team, which traced its origins to June 2024. The extension had been available through the official Chrome Web Store, adding an element of legitimacy that many users rely on when evaluating browser tools. It mimicked common features from reputable trading helpers: detecting token names, integrating data from services like DexScreener, and requesting familiar wallet permissions. These design choices were intentional, aiming to lower suspicion and leverage the credibility of well-known Solana wallets such as Phantom and Solflare.
Behind the façade, however, the infrastructure showed clear signs of malicious intent. The extension communicated with a domain lacking any functional website and featuring a simple blank page. Its supposed official website was parked rather than hosting an operative service. Even the backend domain contained spelling errors—subtle indicators that the developers did not intend to build a legitimate product. Meanwhile, the code was heavily obfuscated, with critical details buried inside convoluted scripts, making manual inspection difficult.
Although the attackers have collected only a modest amount so far, researchers emphasized that the system was engineered for growth. With more users or higher-value traders, the cumulative losses could have increased substantially. Analysts noted that the limited funds gathered—just under seven dollars in total—likely reflect early detection rather than a lack of ambition.
The incident serves as a pointed reminder for Solana users and the broader crypto community. Browser extensions that interact with wallets pose inherent risks, especially when discovered through generic search results. Researchers recommend installing wallet tools exclusively from verified publisher pages and reviewing all transaction instructions before signing. Crypto Copilot may not have achieved large damage, but its method exposes vulnerabilities that attackers will almost certainly continue to target.



