@testnetnew
Crypto Copilot, an extension that allows users to swap Solana tokens directly on X, has been found to have been secretly inserting hidden transfer orders into every transaction since June.
The way it works is very sophisticated, the transaction is still sent to Raydium, but it is accompanied by an automatic transfer order of SOL, while the interface is still displayed normally without a fee notification:
- Transactions under 2.6 SOL: lose 0.0013 SOL
- Transactions over 2.6 SOL: lose 0.05% - Example: swapping 100 SOL will lose ~0.05 SOL
Security experts warn that the Chrome extension ecosystem has long been a fertile ground for crypto scams due to its huge user base and ability to deeply interfere with the browser.