Solana-based Jupiter alerts of malicious Chrome extension draining wallets

As a seasoned analyst with years of experience in the cryptocurrency market, I’ve seen my fair share of scams and malicious activities. The recent incident involving the “Bull Checker” Chrome extension targeting Solana users is yet another reminder that we must always remain vigilant in this digital frontier.


Warning: Be cautious of the Chrome extension named “Bull Checker.” According to Jupiter Exchange, this suspicious software is designed to infiltrate accounts of Solana users.

Following reports from numerous Solana Decentralized Finance users about emptying their cryptocurrency wallets, the exchange issues a cautionary statement.

On August 19th, the Jupiter team posted an update on their platform, revealing that they thoroughly examined user complaints and successfully found the malicious web browser add-on in question.

Over the past week, we’ve been notified about a few instances where Solana DeFi users experienced unauthorized drainage of their funds.

Following an in-depth probe, we have pinpointed a harmful Chrome extension named “Bull Checker” as the culprit. This malicious software appears to have targeted multiple users…

— Jupiter 🪐 (@JupiterExchange) August 19, 2024

According to their post, Bull Checker extension has been focusing on members of diverse Solana communities on the Reddit social network. The team mentions that while this extension enabled users to work as usual with applications on the Solana platform, it inserted harmful commands into transactions in certain instances when users interacted with these applications (dapps). These transactions then moved users’ tokens to a different account.

During installation, Bull Checker requests authorization to access and modify all data on the website, a demand which the Jupiter team considers superfluous for a read-only extension designed to let users merely view meme coin holders’ information.

Despite this issue serving as a significant warning sign, it seems that numerous users persisted in downloading and utilizing the extension nonetheless.

Meow, Jupiter Exchange founder

Reddit-promoted Chrome extension targets Solana users

It is said that a mysterious Reddit user, known as “Solana_OG,” apparently advocated for the use of an extension. This individual is believed to have approached various Solana subreddit members interested in trading Solana meme tokens, enticing them to install the extension.

In one of their Reddit posts, Solana_OG claimed to have made $3,000 in a week by using the extension.

At the time I’m writing this, it appears that the questionable extension has been taken down from the Chrome Web Store, displaying a message, “This item is not available.” Despite this, the Jupiter exchange team urges users to remain vigilant for potentially harmful extensions. They encourage the crypto community to exercise caution when dealing with extensions requesting both “read” and “change” permissions.

Jupiter advises users to be cautious about all suggestions and well-known tools since tricksters could employ social engineering or astroturfing, which is a deceptive tactic that makes a coordinated online effort appear as genuine public feedback. However, the project has guaranteed users that it didn’t discover any weaknesses in the significant dApps or Solana wallets during its examinations.

Read More

Sorry. No data so far.

2024-08-20 10:28