Crypto Copilot is a malicious Chrome extension targeting Solana traders. Marketed as a tool to trade crypto directly from X with real-time insights and instant execution, it connects to Solana wallets such as Phantom and Solflare, uses DexScreener API for token data, and routes trades through Raydium. Its core malicious behavior is to append a hidden SystemProgram.transfer instruction to every Solana swap transaction before signature, siphoning funds to a hardcoded attacker-controlled wallet without disclosure in the user interface or Chrome Web Store listing. Reported fee logic is a minimum of 0.0013 SOL or 0.05% of the trade amount, whichever is greater; for trades over 2.6 SOL, the percentage fee applies. The attacker wallet identified in reporting is Bjeida13AjgPaUEU9xrh1iQMwxZC7QDdvSfg73oxQff7. The extension uses heavily obfuscated, minified code with variable renaming to conceal the theft logic and communicates with backend infrastructure at crypto-coplilot-dashboard.vercel[.]app; the related domain cryptocopilot[.]app was reported as parked/non-functional. The extension also used a hardcoded Helius API key and referenced multiple RPC nodes, while tracking wallet usage, points, and referrals to mimic a legitimate product ecosystem. It was published on the Chrome Web Store by user sjclark76, with reporting citing publication dates of May 7, 2024 and June 18, 2024. The operator was also associated with sjclark76@gmail[.]com and extension ID iaemdpdnmdkaphnmcogmcgcmhhafcifd. High-confidence targeting is Solana users, particularly those swapping via Raydium; users are unlikely to notice the theft unless they inspect transaction instructions before signing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crypto Copilot is a malicious Chrome browser extension that targets users performing Solana swap transactions, surreptitiously injecting an additional transfer to siphon a portion of the funds to an attacker-controlled wallet. It uses obfuscation techniques to hide its behavior and communicates with attacker infrastructure to report user activity.
Crypto Copilot is a malicious Chrome extension targeting Solana traders. It masquerades as a trading convenience tool but secretly injects an additional transfer into every swap, siphoning funds to an attacker-controlled wallet. The extension uses obfuscated code to hide this behavior and communicates with suspicious backend infrastructure, providing the operator with visibility into user wallets and trading activity. It is designed to appear legitimate while extracting recurring fees from unsuspecting users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.