Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Crypto Copilot is robbing users with a hidden Solana transaction fee

A malicious Chrome extension named Crypto Copilot injects a hidden Solana transfer fee into legitimate Raydium swap transactions.

byKerem Gülen
November 27, 2025
in Cybersecurity, DeFi & Blockchain, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail

Cybersecurity researchers at Socket uncovered the malicious Chrome extension Crypto Copilot, which injects hidden Solana transfer fees into Raydium swap transactions on the Chrome Web Store. Published by user sjclark76 on May 7, 2024, the extension has 12 installs and remains available for download.

The extension presents itself as a tool for trading cryptocurrency directly on X, providing real-time insights and seamless execution. Behind this facade, Crypto Copilot manipulates Solana-based transactions executed on Raydium, a decentralized exchange and automated market maker built on the Solana blockchain. When users initiate a swap through Raydium, the extension activates obfuscated code that appends an additional instruction to the transaction before it reaches the user’s signature stage.

This injected instruction consists of a SystemProgram.transfer method, which directs funds from the user’s wallet to a hard-coded address controlled by the attacker. The transfer amount constitutes a minimum of 0.0013 SOL or 0.05 percent of the total trade value, whichever is greater. For swaps exceeding 2.6 SOL, the fee escalates to 2.6 SOL plus 0.05 percent of the swap amount. Socket security researcher Kush Pandya detailed the mechanism in a report released on Tuesday, stating, “Behind the interface, the extension injects an extra transfer into every Solana swap, siphoning a minimum of 0.0013 SOL or 0.05 % of the trade amount to a hard-coded attacker-controlled wallet.”

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

To evade detection, the malicious code employs minification techniques and renames variables, rendering the script difficult to analyze. Users encounter no visible indication of this alteration during the transaction process. The extension’s user interface displays only the standard swap details, omitting any reference to the hidden fee. As a result, individuals typically approve the transaction without awareness of the deduction unless they manually review each instruction prior to signing.

Crypto Copilot integrates with a backend server at crypto-coplilot-dashboard.vercel.app, where it registers connected wallets, retrieves points and referral information, and logs user activities. The associated domain cryptocopilot.app serves no actual product and functions solely as deceptive infrastructure. The extension further bolsters its appearance of legitimacy by incorporating services from DexScreener for market data and Helius RPC for blockchain interactions.

The destination for the siphoned funds is a personal wallet, distinct from any protocol treasury, which complicates user verification. Pandya emphasized this subtlety, noting, “Because this transfer is added silently and sent to a personal wallet rather than a protocol treasury, most users will never notice it unless they inspect each instruction before signing.” He added that the overall setup prioritizes evading platform scrutiny, observing, “The surrounding infrastructure appears designed only to pass Chrome Web Store review and provide a veneer of legitimacy while siphoning fees in the background.”


Featured image credit

Tags: Crypto Copilotsolana

Related Posts

How Zesty uses AI to find your next meal

How Zesty uses AI to find your next meal

December 17, 2025
YouTube Gaming opens Playables Builder beta with Gemini 3

YouTube Gaming opens Playables Builder beta with Gemini 3

December 17, 2025
Watch Instagram Reels on TV with new Fire TV app

Watch Instagram Reels on TV with new Fire TV app

December 17, 2025
Netflix secures 14 iHeartMedia video podcasts for 2026

Netflix secures 14 iHeartMedia video podcasts for 2026

December 17, 2025
Google launches email assistant CC powered by Gemini

Google launches email assistant CC powered by Gemini

December 17, 2025
Steam Replay 2025 reveals your top games of the year

Steam Replay 2025 reveals your top games of the year

December 17, 2025

LATEST NEWS

How Zesty uses AI to find your next meal

YouTube Gaming opens Playables Builder beta with Gemini 3

Watch Instagram Reels on TV with new Fire TV app

Netflix secures 14 iHeartMedia video podcasts for 2026

Google launches email assistant CC powered by Gemini

Steam Replay 2025 reveals your top games of the year

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.