Security Alert For Solana Users: Don’t Use This Chrome Extension

Share This Post

A critical warning has been issued for users of Solana-based decentralized finance (DeFi) platforms about a malicious Chrome extension known as “Bull Checker.” This alert was issued by Jupiter, a leading decentralized exchange aggregator on the Solana blockchain, following investigative collaboration with cybersecurity experts and community support.

A Warning for All Solana Users

Jupiter’s research team, in partnership with Offside Labs and key community moderators, uncovered that “Bull Checker” was responsible for unauthorized token transfers from user wallets. Reports began surfacing over the last week about unusual token drains, which prompted a detailed analysis. “Following multiple reports from our users, our investigation identified the ‘Bull Checker’ Chrome extension as a conduit for these thefts,” Jupiter Research writes. The extension, which was supposedly designed to allow users to view holders of memecoins, actually possessed capabilities to alter transaction data.

The extension operates by waiting for a user to interact with a legitimate dApp on the official domain. It then modifies the transaction sent to the wallet for signing. Although the simulation results appear normal, the transactions are manipulated to include instructions that transfer tokens to an attacker’s wallet. “What is particularly insidious about this extension is that it injects malicious code that remains undetected during typical transaction simulations,” added Meow, the pseudonymous founder of Jupiter.

Through technical examination, it was revealed that the attack vectors utilized by “Bull Checker” are sophisticated. “We noticed that the extension could replace the wallet adapter’s signTransaction method with its own implementation, which would then send the unsigned transaction to a remote server. This server attaches a call to a drain program before returning it for user approval,” explained Meow.

This discovery was substantiated by reviewing specific transaction examples where malicious instructions were added to routine transactions. In one of the detailed transaction reviews, the exploited user executed what seemed to be a standard transaction that ended up transferring 0.06 SOL and their token authority to an exploiter’s address identified as 8QYkBcer7kzCtXJGNazCR6jrRJS829aBow12jUob3jhR.

The modus operandi of the malicious extension involved multiple stages. First, the extension monitored the SOL balance of the victim’s account during the transaction simulation, which typically showed a zero balance leading to the abortion of malicious instructions. However, immediately after the simulation, the attacker executed a sequence of bundled transactions that included sending SOL to increase the balance, executing the malicious transaction, and then pulling SOL out, all unbeknownst to the user.

“Bull Checker” was initially promoted through an anonymous Reddit account, known as “Solana_OG,” which appeared to target users interested in trading memecoins. This should have been a red flag given the lack of transparency and the nature of the advertised functionality. Unfortunately, the extension still found its way onto the computers of several unsuspecting users.

The ongoing investigation has revealed that while “Bull Checker” has been identified and publicized, other malicious extensions with similar capabilities might still exist. Users are urged to exercise extreme caution with any extension that requests broad permissions to read and change all data on websites. “Users need to verify the legitimacy and the necessity of any extension, especially those interacting deeply with financial transactions or wallet data,” cautioned Meow.

In response to these types of threats, Blowfish has recently released a feature known as SafeGuard aimed at preventing simulation spoofing attacks, which is now being adopted by multiple Solana wallets. This new security measure enhances the integrity of transaction verifications, providing an additional layer of protection against similar exploits.

At press time, Solana traded at $146.67.

Solana price

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Solana (SOL) Path To New Highs: Analyst Eyes $160 As Critical Breakpoint

Solana is testing a crucial level after weeks of volatile price action and market uncertainty Following the Federal Reserve’s interest rate cut announcement, Solana surged 26% but quickly

PEPE Bulls Lose Momentum, Downside Risk Grows After Failing To Hold $0.00000963

PEPE’s recent price action is raising concerns among traders, as bullish momentum appears to be fading After attempting to rebound, the token faced strong resistance at the $000000963 mark,

Bitcoin Holds Steady As Bullish Breakout Awaits These Conditions – Details

According to data from CoinMarketCap, Bitcoin currently hovers near the $62,000 price mark with no significant movement in the past day Notably, the premier cryptocurrency has slipped into a minor

Last Week Featured Bullish Continuation

This editorial is from last week’s newsletter, Week in Review, with some slight tweaks to dates so the article makes sense Subscribe to the newsletter to get this editorial the second it’s

AI Powerhouse Openai Raises $6.6B Achieving a $157B Valuation

AI startup Openai reported closing a funding round led by Thrive Capital and the participation of other tech companies like Microsoft and Nvidia The $66 billion raised would be used to expand its set

Crypto Ponzi Scheme Leader Sentenced To 10 Years By US Court

David Carmona, founder of the cryptocurrency Ponzi scheme IcomTech, has received a 10-year prison sentence following a court ruling in the last week This development was revealed on October 4  by