TLDR
The malicious extension was Crypto Copilot, a Chrome add?on that siphoned SOL during Raydium swaps by injecting a hidden transfer instruction per a security write?up on the incident (details).
- Crypto Copilot posed as a trading assistant and routed swaps through Raydium while adding a stealth SOL transfer to an attacker wallet (report).
- The extra instruction was easy to miss because many wallets show only summary views unless you expand all instructions (report).
Deep Dive
1. Extension Identity
Crypto Copilot is the extension named in recent reporting as siphoning SOL during swaps. It masqueraded as a helpful trade from X posts tool, connected to common wallets, surfaced price data, and routed swaps via Raydium, but slipped in a second instruction that sent a small amount of SOL to an attacker address (details).
If you installed Crypto Copilot, assume risk. Remove it, and scrutinize recent transactions for unexpected SOL transfers adjacent to legitimate swaps.
2. How The Theft Worked
The method relied on Solanas multi?instruction transactions. During a Raydium swap, the extension added a hidden transfer instruction (fixed or percentage?based) to the attacker. Wallet UIs that default to summary views made this easy to miss unless users expanded instruction lists (report).
- Obfuscated JavaScript concealed the logic, while a benign?looking UI created trust (report).
- On chain, theft appears as small SOL transfers adjacent to genuine swap activity, complicating detection (report).
Before signing, expand and review all transaction instructions. Afterward, scan for small outbound SOL transfers in the same transaction as a swap.
Conclusion
The extension named in reports is Crypto Copilot, which siphoned SOL by injecting a hidden transfer instruction alongside Raydium swaps. The practical takeaway is simple: remove untrusted extensions, expand and verify every transaction instruction before signing, and review past swap transactions for unexplained SOL outflows.
