
星球日报|Nov 27, 2025 14:23
[Security Company: Malicious Google Chrome Extension Steals Portions of SOL Tokens in Secret]
Odaily Planet Daily News: A Google Chrome browser extension allows users to conduct transactions on Solana while secretly siphoning a portion of the fees from each transaction into the creator's wallet. According to a report released by cybersecurity company Socket on Tuesday, it was discovered that Crypto Copilot injects additional transfers during each Solana Swap, stealing at least 0.0013 SOL or 0.05% of the transaction amount. On the backend, Crypto Copilot uses the decentralized exchange Raydium to execute swaps for users but adds a second instruction to transfer SOL from the user to the attacker. The user interface only displays swap details, while the wallet confirmation screen "only summarizes transaction information without showing specific instructions." Reportedly, Crypto Copilot is a convenient tool that allows Solana traders to execute swap transactions directly via Twitter. (Cointelegraph)
Timeline