Malicious Chrome extensions secretly steal Solana transaction funds

According to Deep Tide TechFlow news on November 27, Cointelegraph reported that cybersecurity company Socket discovered a malicious Chrome extension named “Crypto Copilot” that is secretly stealing funds from users' Solana transactions. This extension allows users to conduct Solana transactions directly from the X social media platform, but injects additional instructions into each transaction, extracting at least 0.0013 SOL or 0.05% of the transaction amount.

Unlike typical wallet-emptying malware, Crypto Copilot executes trades using the Raydium decentralized exchange while adding a second instruction to transfer SOL to the attacker's wallet, with the user interface only displaying a transaction summary and hiding the individual operation instructions.

Since the release of this extension on June 18, 2024, there are currently only 15 users. Socket has submitted a takedown request to the Chrome Web Store security team. Security experts remind users that the Chrome extension ecosystem has long been a popular target for cryptocurrency scams due to its large user base and scalable design.

SOL-2.91%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)