Security Firm: Malicious Chrome Extension 「Crypto Copilot」 Secretly Steals Funds from User's Solana Transactions
BlockBeats News, November 27th, according to Cointelegraph, cybersecurity firm Socket has discovered a malicious Chrome extension named "Crypto Copilot" that is surreptitiously siphoning funds from users' Solana transactions. This extension allows users to directly conduct Solana transactions from X social media platforms but injects additional instructions into each transaction, siphoning off at least 0.0013 SOL or 0.05% of the transaction amount.
Unlike typical wallet-draining malware, Crypto Copilot leverages the Raydium decentralized exchange to execute transactions while adding a second instruction to transfer SOL to the attacker's wallet, with the user interface only displaying a transaction summary, concealing the separate operation instruction. Since its release on June 18, 2024, the extension has only had 15 users. Socket has submitted a takedown request to the Chrome Web Store security team. Security experts remind users that the Chrome extension ecosystem has long been a prime target for cryptocurrency scams due to its large user base and extensible design.
You may also like

How to View the Neobank Era Post Crypto Boom?

《The Economist》: In Asia, stablecoins are becoming a new financial infrastructure

Why Most Cryptocurrencies Are Designed to Be Non-Reinvestment Assets

From Lloyd's Coffee House to Polymarket: Prediction Markets are Rethinking the Insurance Industry

a16z Partner Manifesto: Boutique VC is Dead, Go Big or Go Home

Untitled
I’m sorry, but it appears there’s no actual content from the original article provided for me to rewrite.…

Bitcoin Experiences Record 23% Decline in Early 2026
Key Takeaways Bitcoin has experienced a record-setting decline of 23% in the first 50 trading days of 2026.…

Whale Holding 105,000 ETH Faces $8.5 Million Loss
Key Takeaways A significant Ethereum holder, often termed a “whale,” has accumulated long positions in 105,000 ETH. The…

Bitcoin Faces Liquidity Challenges as $70,000 Rebound Struggles
Key Takeaways Bitcoin’s attempts to break the $70,000 mark face significant challenges due to weak liquidity and market…

Newly Created Address Withdraws 7,000 ETH from Binance
Key Takeaways A newly created cryptocurrency address withdrew 7,000 ETH from Binance within an hour, totaling $13.55 million.…

Balancer Halts reCLAMM-Linked Liquidity Pools for Security Check
Key Takeaways Balancer has temporarily halted reCLAMM-related liquidity pools due to security concerns. A report from the bug…

Whales Take on Ethereum: Major Profits from Leveraged Short Positions
Key Takeaways Three Ethereum whales are collectively reaping over $24 million in unrealized profits from short positions. The…

SlowMist Unveils Security Vulnerabilities in ClawHub’s AI Ecosystem
Key Takeaways SlowMist identifies 1,184 malicious skills on ClawHub aimed at stealing sensitive data. The identified threats include…

Matrixport Anticipates Crypto Market Turning Point as Liquidity Drains
Key Takeaways Matrixport notes a surge in Bitcoin’s implied volatility due to a sharp price drop. Bitcoin price…

Bitmine Withdraws 10,000 ETH from Kraken
Key Takeaways A newly created address linked to Bitmine withdrew 10,000 ETH from Kraken. The withdrawal value amounts…

In the face of the Quantum Threat, Bitcoin Core developers have chosen to ignore it

Don't Just Focus on Trading Volume: A Guide to Understanding the "Fake Real Volume" of Perpetual Contracts

Crypto Price Prediction Today 18 February – XRP, Bitcoin, Ethereum
Key Takeaways XRP’s potential as a replacement for SWIFT is bolstered by regulatory approvals, potentially driving its price…
How to View the Neobank Era Post Crypto Boom?
《The Economist》: In Asia, stablecoins are becoming a new financial infrastructure
Why Most Cryptocurrencies Are Designed to Be Non-Reinvestment Assets
From Lloyd's Coffee House to Polymarket: Prediction Markets are Rethinking the Insurance Industry
a16z Partner Manifesto: Boutique VC is Dead, Go Big or Go Home
Untitled
I’m sorry, but it appears there’s no actual content from the original article provided for me to rewrite.…