Close Menu
Crypto Breaking News
    12 January 2026
    FacebookX (Twitter)InstagramYouTubeLinkedInTikTokTelegramRSS
    Crypto Breaking News
    • News
      • Press Release
      • Press Releases by PR Newswire
      • News by Coincu
      • News by Blockchain Wire
      • News by CoinPedia
      • Events
      • Exchanges
      • Crypto Wallets
      • Featured
      • Blockchain Life
      • Bitcoin Conference
      • Bitcoin
      • Ethereum
      • Solana
      • Cardano
      • Ripple
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    0Shopping Cart
    Login
    Crypto Breaking News
    0Shopping Cart
    Home » Crypto News » Hidden Fee Scam in Plain Sight: How Crypto Copilot Quietly Drained Solana Traders  
    Crypto News

    Hidden Fee Scam in Plain Sight: How Crypto Copilot Quietly Drained Solana Traders  

    28 November 2025
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Hidden Fee Scam In Plain Sight: How Crypto Copilot Quietly Drained Solana Traders  
    Hidden Fee Scam In Plain Sight: How Crypto Copilot Quietly Drained Solana Traders  

    Security researchers disclosed that Crypto Copilot, a Chrome extension, has been consistently skimming SOL from users trying to swap on Raydium. Instead of directly draining wallets, the extension attaches a hidden transfer instruction to legitimate transactions, siphoning at least 0.0013 SOL or 0.05% of the trade value directly into the wallet of an attacker.

    How the Hidden Transfer Slipped Past Wallet Screens  

    The extension, launched on the Chrome Web Store on June 18, 2024, by a developer account listed as “sjclark76,” positioned itself as the perfect companion for traders glued to X, promising instant swaps directly from the feed by integrating with DexScreener for pricing, Helius for blockchain access, and mainstream wallets like Phantom and Solflare.

    When a user initiates a swap, the extension silently modifies the transaction before it ever reaches the wallet. 

    The malicious code injects an additional SystemProgram.transfer instruction that routes funds to a hardcoded recipient address. Because the legitimate swap and the theft are combined into a single atomic transaction, the wallet’s confirmation screen shows only the expected trade details. The extra transfer remains invisible unless the user consciously expands and examines every instruction, a step only few traders take.

    The extension’s source code is heavily compressed and hidden, while its supposed official website, cryptocopilot.app, remains a parked GoDaddy domain with no functional content. As of November 27, 2025, the extension, Crypto Copilot, is still available on the Chrome Web Store with only 12 and 15 known installations.

    What Users Must Do Before It’s Too Late

    The siphon scheme was disclosed by security company Socket on November 25, 2025, after fully reverse-engineering the extension. According to researcher Kush Pandya, the transfer is silently added to and forwarded to a personal wallet rather than to any protocol treasury, meaning most victims never notice unless they carefully review every instruction before signing.

    Socket has submitted a removal request to Google. The incident follows a series of similar attacks on Solana users, including the Bull Checker extension flagged in August 2024 and another high-ranking wallet that was flagged earlier in November 2025, which operate using similar tactics.

    Users who have ever installed Crypto Copilot are advised to remove the extension immediately, move remaining funds to a new wallet, and revoke all associated approvals using services such as revoke.cash. 

    Moving forward, traders and investors are advised to manually review every transaction instruction before signing, particularly when using third-party browser extensions to interact with Solana protocols.

    Crypto Investing Risk Warning
    Crypto assets are highly volatile. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. Read the full disclaimer

    Affiliate Disclosure
    This article may contain affiliate links. See our Affiliate Disclosure for more information.

    Toheeb Kolade
    • X (Twitter)

    Toheeb is an insightful blockchain reporter with deep knowledge of cryptocurrencies. With years of experience in financial journalism, Toheeb covers the latest developments in blockchain technology, cryptocurrency trends, decentralized finance (DeFi), and regulatory updates. Known for breaking news and in-depth analysis, Toheeb brings new angles on how blockchain is transforming industries and changing the global economy. From uncovering market movements to providing expert commentary on new technologies, Toheeb is dedicated to keeping readers informed about the developments in blockchain-related topics.

    Related Posts

    Crypto Etps Lose $454m In Outflows As Bitcoin Bears Dominate

    Crypto ETPs Lose $454M in Outflows as Bitcoin Bears Dominate

    Binance Puts Content Creators In The Spotlight At The 1 Billion Followers Summit

    Binance Puts Content Creators in the Spotlight at the 1 Billion Followers Summit

    Search Crypto News

    Join 15,000+ Crypto Followers

    • Facebook2.3K
    • Twitter4.3K
    • Instagram5.6K
    • LinkedIn4K
    • Telegram52
    • Threads800

    Newsletter

    10% off on first order!

    Privacy Policy

    Check your inbox or spam folder to confirm your subscription.

    Kraken Pro 300x250
    Crypto.com

    Featured Crypto News

    Uae Real Estate Heads Into 2026 After Aed 680b Year Of Transactions

    UAE Real Estate Heads into 2026 After AED 680B Year of Transactions

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Contacts:
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions

    advertising

    Megacampus Summit Dubai 2026
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Osom One & Web3 Digital

    Osom One Limited | Company number: 12393319 | 3rd Floor 86 - 90 Paul Street, London, United Kingdom, EC2A 4NE

    Web3 Digital L.L.C-FZ | License Number: 2527596.01 | Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!

    Sign In or Register

    Welcome Back!

    Login below or Register Now.

    Lost password?

    Register Now!

    Already registered? Login.

    A password will be e-mailed to you.