financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Solana Users Targeted by ‘Bull Checker’ Chrome Extension Scam
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Solana Users Targeted by ‘Bull Checker’ Chrome Extension Scam
Aug 20, 2024 3:39 PM

A new malicious browser extension called the Bull Checker is reportedly targeting Solana users on Reddit by masquerading as a meme coin tracker.

This extension evades detection systems and has drained Solana users wallets.

Solana Users Targeted

In the past week, Jupiters pseudonymous founder, Meow, reported that a few Solana DeFi users experienced unauthorized token drains. Through a thorough investigation with partners, they traced the issue to Bull Checker, which had been targeting users on various Solana-related subreddits.

This extension allowed users to interact normally with decentralized apps (dApps), but it secretly transferred tokens to unauthorized wallets upon transaction completion. Jupiters founder stressed that no vulnerabilities were found in the dApps or wallets themselves.

They urged users to remove the Bull Checker extension or any similar ones with extensive permissions that they cannot trust immediately.

Bull Checker is designed as a read-only extension intended to display meme coin holders. Ideally, such an extension should not require permission to read or write data on all websites, which should have raised concerns for users. Despite this, several users proceeded to install and use it.

Once installed, Bull Checker waits until a user interacts with a standard dApp on its official domain, then alters the transaction before it is signed by the wallet. The modified transaction still appears normal in the simulation, concealing its true intent as a drainer.

While researching the Chrome extension, Jupiters founder also discovered that it was promoted by an anonymous Reddit account, Solana_OG. This individual seemed to target users looking to trade meme coins and lured them to download the extension.

Keen Eye for Red Flags

Meow issued a strong warning to users, stressing the importance of skepticism when encountering recommendations on Reddit or other media platforms, regardless of how many upvotes or positive comments they receive.

The founder highlighted the dangers of astroturfing and social engineering, where bad actors can manipulate public perception to spread harmful tools like the Bull Checker extension. They further went on to add that extensions that request extensive permissions, such as the ability to read and modify all website data, should be treated with extreme caution.

While we have identified one malicious extension, there might still be other malicious extensions out there. There have been reports of other drains that we have not been able to track down. If you suspect an extension contains malware, particularly if they have both “read” and “change” permissions, uninstall it immediately.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Bitcoin Bounces Back to $95K as Bullish Sentiment Returns
Bitcoin Bounces Back to $95K as Bullish Sentiment Returns
Jan 13, 2025
Bitcoin has recovered from its 2025 and 8-week low of just below $90,000 during late trading on Monday, Jan. 13. The asset gained around $5,000 over the past 12 hours from that drop or so to tap the $95,000 level during trading in Asia on Tuesday morning. BTC is now back in the middle of its range-bound channel that formed...
7 Million OpenSea Addresses Leaked in 2022 Breach, SlowMist Confirms
7 Million OpenSea Addresses Leaked in 2022 Breach, SlowMist Confirms
Jan 13, 2025
The data breach OpenSeas email service provider which occurred in June 2022 resulted in the leak of 7 million email addresses. Experts have found that this includes many well-known people, firms as well as key opinion leaders (KOLs) in the crypto industry. OpenSea Breach According to the latest update shared by SlowMists pseudonymous chief information security officer, 23pds, the leaked...
Bitcoin Recovers $7K Following Sub
Bitcoin Recovers $7K Following Sub
Jan 14, 2025
Bitcoins volatile rollercoaster continued in the past 24 hours as the asset plunged below $90,000 for the first time in months but has jumped by over seven grand since then. The altcoins are also in recovery mode, with ETH reclaiming $3,200, while DOGE has jumped by over 7% daily. BTC Bounces Off The primary cryptocurrency was in a freefall state...
Tether to Relocate Business to El Salvador Following Acquisition of DASP License
Tether to Relocate Business to El Salvador Following Acquisition of DASP License
Jan 14, 2025
The largest stablecoin issuer has announced that it is relocating its business to the Bitcoin-friendly El Salvador after acquiring a Digital Asset Service Provider (DASP) license in the country. According to an official release, Tether and its subsidiaries will be located in El Salvador after the company completes all formalities for the move. The stablecoin issuer will also establish its...
Copyright 2023-2025 - www.financetom.com All Rights Reserved