Briefing

A supply chain attack has been identified on the Solana network, leveraging a malicious Chrome browser extension named “Crypto Copilot” to silently skim assets from user transactions. This attack vector bypassed standard wallet security summaries by injecting a second, unauthorized instruction into a legitimate swap transaction, which was then executed on-chain without user knowledge. The primary consequence is a continuous, long-tail financial drain on affected users, as the skimming mechanism was subtle enough to evade detection over a period of months. The single most important detail quantifying the event is the skimming rate of 0.05% of the swap value, or a minimum of 0.0013 SOL per transaction, designed for stealth and cumulative theft.

A central metallic mechanism anchors four translucent, white-textured blades, intricately veined with vibrant blue liquid-like channels. These dynamic structures emanate from the core, suggesting rapid data flow and advanced computational processing crucial for modern distributed ledger technologies

Context

The prevailing attack surface for the digital asset ecosystem includes third-party applications and browser extensions, which often operate with high-level permissions, creating a significant point of failure. This class of vulnerability is an evolution of the traditional wallet drainer, moving from an immediate, high-volume theft to a subtle, continuous skimming model. The inherent design of many blockchain transaction formats, which allow for multiple instructions to be batched and executed, creates an exploitable gap between the simplified transaction summary shown to the user and the full set of instructions submitted to the network.

A detailed overhead perspective showcases a high-tech apparatus featuring a central circular basin vigorously churning with light blue, foamy bubbles. This core is integrated into a sophisticated framework of dark blue and metallic silver components, accented by vibrant blue glowing elements and smaller bubble clusters in the background

Analysis

The incident’s technical mechanics centered on a malicious modification within the “Crypto Copilot” Chrome extension. When a user initiated a standard token swap through a legitimate decentralized exchange like Raydium, the extension intercepted the transaction data before it reached the user’s wallet for signing. The attacker’s code then programmatically appended a second, hidden instruction to the transaction payload, routing a small fraction of the output tokens to the attacker’s address.

The user interface and the wallet confirmation prompt only displayed the details of the legitimate swap instruction, successfully masking the secondary, malicious skimming instruction. This chain of cause and effect was successful because the Solana network executed all signed instructions atomically, including the hidden one, leveraging the user’s implicit trust in the browser extension.

A dynamic blue liquid splash emerges from a sophisticated digital interface displaying vibrant blue data visualizations. The background reveals intricate metallic structures, suggesting a robust hardware component or network node

Parameters

  • Attack Vector → Malicious Chrome Extension – The core vector was a compromised third-party browser tool used for “trade instantly from Twitter.”
  • Affected BlockchainSolana Network – The exploit targeted the instruction-based transaction model of the Solana blockchain.
  • Skimming Rate → 0.05% per transaction – The percentage of the swap value silently diverted to the attacker’s address, or 0.0013 SOL minimum.
  • Duration of Operation → Active since June 2025 – The extension was operational and skimming funds for several months before public disclosure.

A sophisticated, modular blue and silver mechanism is depicted, densely enveloped by countless small, translucent spherical particles that appear to be in motion. The central structure features prominent hexagonal elements and a sleek, industrial design, with a stream of particles entering and exiting various components

Outlook

Immediate mitigation requires users to conduct a full audit of all installed browser extensions and revoke token approvals granted to any suspicious or non-essential smart contracts. This incident will likely establish a new security best practice, demanding that wallet providers implement more granular and transparent transaction simulation tools capable of parsing and displaying all instructions within a single transaction bundle. The contagion risk is high for other ecosystems utilizing multi-instruction transaction models, prompting a necessary re-evaluation of security posture for all front-end interfaces that interact with on-chain protocols.

White, interconnected modular structures dominate the frame, featuring a central nexus where vibrant blue data streams burst forth, illuminating the surrounding components against a dark, blurred background. This visual representation details the complex architecture of blockchain interoperability, showcasing how diverse protocol layers facilitate secure cross-chain communication and atomic swaps

Verdict

The incident confirms that supply chain attacks leveraging subtle transaction manipulation represent a persistent, long-tail risk that traditional wallet interfaces fail to mitigate.

Solana network, Chrome extension, Supply chain attack, Wallet drainer, Transaction skimming, Hidden instruction, On-chain theft, Permission abuse, Swap execution, Decentralized exchange, Browser security, Token transfer, Digital asset risk, Continuous theft, Low volume skimming, Web3 security, User interface spoofing, On-chain forensic, Token allowance, Security posture Signal Acquired from → binance.com

Micro Crypto News Feeds