Fun

Malicious ‘bull checker’ Chrome extension found targeting Solana users

News Feed - 2024-08-20 02:08:10

Tom Mitchelhill3 hours agoMalicious ‘bull checker’ Chrome extension found targeting Solana usersDecentralized exchange aggregator Jupiter has alerted users of a malicious browser extension that managed to sneak through Solana’s drainer checks.769 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onDecentralized exchange aggregator Jupiter says it has identified a new malicious browser extension. The extension has already drained the wallets of several Solana users and can even sneak past detectors.


In an Aug. 20 research post, pseudonymous Jupiter founder Meow said “Bull Checker” — a nefarious Google Chrome browser extension — had been targeting Solana users on Reddit, advertising itself as an extension to view all the holders of specific memecoins. Source:Jupiter


“If you have this extension (or similar extensions with extensive permissions you cannot trust), please remove it immediately,” wrote Jupiter in an Aug. 19 X post.


Meow said the extension was able to pass Solana simulation checks and “appear normal” but was actually a drainer designed to steal funds from users’ wallets.


“After installing Bull Checker, it will wait till a user interacts with a regular DApp [decentralized application] on the official domain, before modifying the transaction sent to the wallet to sign. After modification, the simulation result will still be ‘normal’ and not appear to be a drainer,” explained Meow.

Meow said the Bull Checker extension asked users to accept permissions to “read and write” data, adding that any legitimate wallet-checking extension should only ever ask for ‘read-only’” permissions. 


“This should have been a major red flag for users, but apparently, several users continued to install and use the extension,” he said. The “Bull Checker” extension asked for permission to read and write data. Source: Jupiter


“Users with this extension would interact with the DApps as per normal, have the simulation show up as normal, but have the possibility of their tokens being maliciously transferred to another wallet upon transaction completion,” he added. 


Related:Solana ETF ‘still in play’ despite Cboe filing removal — VanEck exec


One of the users advertising the malicious extension on Reddit said they had used it to make $3,000 in the last week without providing any further specifics. 


Jupiter reassured users that no vulnerabilities were discovered in any of the major decentralized applications or wallets on the Solana network during its investigation. 


The discovery of the “Bull Checker” extension comes less than two weeks after Solana-based decentralized futures exchange Cypher Protocol halted its smart contract system in the wake of an estimated $1 million exploit.


Meanwhile, on July 8, Matthias Mende, co-founder of the Dubai Blockchain Center, told Cointelegraph he had fallen victim to an exploit where a hacker managed to steal over $100,000 in Solana (SOL) from his Phantom Wallet following his participation in a memecoin presale event. 


Mende said he still doesn’t know how the hack occurred. 


Magazine:5 dangers to beware when apeing into Solana memecoins# Blockchain# Altcoin# Hackers# Scams# DeFi# Solana# MemecoinAdd reaction

News Feed

Bitcoin’s Hashrate Taps an All-Time High, Next-Gen Machine Deployment Could Push it Much Higher
Bitcoin"s Hashrate Taps an All-Time High, Next-Gen Machine Deployment Could Push it Much Higher Bitcoin’s hashrate has once again reached an all-time high (ATH) this year, a
US deputy treasury secretary calls for additional tools to sanction crypto firms
Turner Wright3 hours agoUS deputy treasury secretary calls for additional tools to sanction crypto firmsWally Adeyemo cited a recent settlement with crypto exchange Binance and sanctions against crypto mixer Sinbad in ca
Tech firms pen letter to EU requesting more time to comply with AI Act
Savannah Fortis11 hours agoTech firms pen letter to EU requesting more time to comply with AI ActTech companies release a joint letter requesting more time from the EU to comply with AI Act requirements, citing challenge
Tom Mitchelhill6 hours agoJPEX scandal masterminds still at large as 11 suspects taken into custody: ReportHong Kong police said the leaders of the JPEX crypto exchange are still at large and are now enlisting the help o
Memecoins are like a ‘risky casino’ — Andreessen Horowitz exec
Prashant Jha11 hours agoMemecoins are like a ‘risky casino’ — Andreessen Horowitz execThe chief technology officer of VC firm Andreessen Horowitz said that memecoins are like risky casinos that deter real builders
XRP Could Hit $9 In Euphoric Fifth Wave, Elliott Wave Analyst Predicts
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Ethereum price lags due to ‘weaker capital rotation,’ but crypto macro uptrend remains
Nancy Lubale3 hours agoEthereum price lags due to ‘weaker capital rotation,’ but crypto macro uptrend remainsETH price has underperformed Bitcoin, but Glassnode analysts say data suggests the crypto market remains in
Report: Nigerian Central Bank Incentive Scheme Failed to Halt Naira Depreciation
Report: Nigerian Central Bank Incentive Scheme Failed to Halt Naira Depreciation The Central Bank of Nigeria (CBN)’s attempt to incentivize the country’s forex market
Full Ban on Crypto in Russia Would Be Counterproductive, Rosfinmonitoring Says
Full Ban on Crypto in Russia Would Be Counterproductive, Rosfinmonitoring Says Russian citizens and businesses already own cryptocurrencies, which is why a complete crypto ban woul
Adidas Originals NFT Compilation Enters Top 50 Collections by Volume, Close to $60M in Sales in 18 Days
Adidas Originals NFT Compilation Enters Top 50 Collections by Volume, Close to $60M in Sales in 18 Days Less than 20 days ago, the German multinational sneaker and sportswear corpo
Billion Dollar Bitcoin Lawsuit Verdict Appealed — Self-Proclaimed Bitcoin Inventor Expects a Win
Billion Dollar Bitcoin Lawsuit Verdict Appealed — Self-Proclaimed Bitcoin Inventor Expects a Win The law firm representing Ira Kleiman has sent a notice of appeal to the Florida
Solana Meme Economy: The Culture That Drives Billions In Volume – Here’s How
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu