A Chrome extension named Crypto Copilot was discovered to be malicious, secretly injecting additional Solana (SOL) transfer instructions into Raydium swap transactions. Marketed as a tool for trading crypto directly from X (formerly Twitter), the extension covertly siphons a minimum of 0.0013 SOL or 0.05% of the trade amount to a hardcoded attacker-controlled wallet, without disclosing this behavior to users. The malicious code is heavily obfuscated and the extension remains available for download on the Chrome Web Store, with takedown requests submitted but not yet actioned.
The extension manipulates the transaction by appending a hidden SystemProgram.transfer instruction before the user signs, making the unauthorized transfer indistinguishable in the wallet confirmation screen. It also communicates with attacker-controlled backend domains to register wallets and report user activity. The extension targets users of popular Solana wallets like Phantom and Solflare, and leverages the Raydium decentralized exchange to execute the fraudulent transfers, leaving users unaware of the hidden platform fee being deducted from each swap.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, researchers reported that Crypto Copilot was still available on the Chrome Web Store and that takedown requests had been submitted. Public reporting also noted the extension had limited distribution, with one source citing 12 installs.
Security researchers determined that Crypto Copilot used obfuscated code, hardcoded wallet addresses, and disposable backend infrastructure to steal funds from users. They also found the extension mimicked legitimate trading tools and reported that the attacker wallet had so far received only relatively small amounts.
After publication, the extension targeted Solana traders using Raydium by appending a concealed transfer to each swap transaction. The hidden fee sent at least 0.0013 SOL or 0.05% of the trade amount to a hardcoded attacker-controlled wallet without user disclosure.
The malicious Chrome extension Crypto Copilot was made available on the Chrome Web Store in 2024. Sources place its publication in early-to-mid 2024, with one report citing May 7, 2024, and another citing June 18, 2024.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.