Malicious Chrome Extension 'Crypto Copilot' Drains Solana Users' Funds

A Chrome extension called 'Crypto Copilot' has been stealing funds from Solana transactions by injecting hidden instructions, cybersecurity firm Socket reports. The extension, which allows users to trade Solana directly from X, siphons at least 0.0013 SOL or 0.05% per transaction by adding a secondary instruction that redirects funds to an attacker's wallet via Raydium DEX, while displaying only transaction summaries to users. Released on June 18, 2024, the extension has 15 users, and Socket has filed a removal request with the Chrome Web Store security team.