Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

NHS rolls out CAR-T therapy for malignant leukemia

Chrome extension found to be injecting hidden Solana transfer fees into Radium Swap

Learn how to identify risks and safely patch using community-maintained tools

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Chrome extension found to be injecting hidden Solana transfer fees into Radium Swap
Identity

Chrome extension found to be injecting hidden Solana transfer fees into Radium Swap

userBy userNovember 26, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 26, 2025Ravi LakshmananBrowser security / Cryptocurrency

Cybersecurity researchers have discovered a new malicious extension in the Chrome Web Store that can insert stealthy Solana transfers into swap transactions and transfer funds to an attacker-controlled crypto wallet.

The extension, named Crypto Copilot, was first published on May 7, 2024 by a user named ‘sjclark76’. The developer describes the browser add-on as offering the ability to “trade cryptocurrencies directly on X with real-time insights and seamless execution.” This extension has had 12 installations and is still available for download at the time of writing.

DFIR retainer service

“Behind the interface, the extension injects additional transfers into every Solana swap, siphoning a minimum of 0.0013 SOL, or 0.05% of the transaction amount, into a hard-coded attacker-controlled wallet,” Sockets security researcher Kush Pandya said in a report on Tuesday.

Specifically, this extension contains obfuscated code that is activated when a user performs a Raydium swap and is manipulated to insert a private SOL transfer into the same signed transaction. Raydium is a decentralized exchange (DEX) and automated market maker (AMM) built on the Solana blockchain.

It works by adding a hidden SystemProgram.transfer util method to each swap before the user’s signature is required, sending the fee to a hardcoded wallet embedded in the code. Fees are calculated based on the trade amount, with a minimum of 0.0013 SOL, 2.6 SOL for trades, and 0.05% of the swap amount for trades above 2.6 SOL. To avoid detection, malicious behavior is hidden using techniques such as minification and variable renaming.

The extension also communicates with a backend hosted on the domain “crypto-coplilot-dashboard.vercel”.[.]app” to register connected wallets, earn points and referral data, and report user activity. Domain and “cryptocopilot”[.]app” does not host the actual product.

CIS build kit

What is notable about this attack is that the user is completely unaware of the hidden platform fees and only the swap details are visible in the user interface. Additionally, Crypto Copilot leverages legitimate services such as DexScreener and Helius RPC to increase surface reliability.

“Because this transfer is added silently and sent to a personal wallet rather than the protocol treasury, most users will not notice it unless they examine each instruction before signing,” Pandya said. “The surrounding infrastructure appears to be designed solely for the purpose of passing Chrome Web Store review and feigning legitimacy while siphoning fees behind the scenes.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEU plans €51 million ‘Choose Europe’ recruitment for researchers in 2027
Next Article NHS rolls out CAR-T therapy for malignant leukemia
user
  • Website

Related Posts

Learn how to identify risks and safely patch using community-maintained tools

November 26, 2025

RomCom uses SocGholish fake update attack to deliver Mythic Agent malware

November 26, 2025

Researchers point to increase in AI phishing and holiday scams, FBI reports $262 million in ATO fraud

November 26, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

NHS rolls out CAR-T therapy for malignant leukemia

Chrome extension found to be injecting hidden Solana transfer fees into Radium Swap

Learn how to identify risks and safely patch using community-maintained tools

EU plans €51 million ‘Choose Europe’ recruitment for researchers in 2027

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.