SlowMist: GitHubs popular Solana tool hides a trap for stealing coins

By: odaily.com|2025/07/03 11:41:20

Odaily News According to the monitoring of the SlowMist security team, on July 2, a victim said that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of increasing the popularity of the project, the user ran the Node.js project with malicious dependencies without any defense, resulting in the leakage of wallet private keys and theft of assets. The entire attack chain involves multiple GitHub accounts to operate in coordination, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses social engineering and technical means, and it is difficult to fully defend within the organization. SlowMist recommends that developers and users be highly vigilant against GitHub projects of unknown origin, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.

You may also like

News thumbnail

ETH Holders Might Need More Patience for Fresh All-Time Highs

As of today, August 15, 2025, many Ether enthusiasts are eagerly watching the charts, hoping for a breakthrough…

crypto insight|2025/08/15 10:10:17
News thumbnail

Why Bitcoin’s Record High Evaporated in Hours: Unpacking the $124,000 to $117,500 Plunge on August 15, 2025

Bitcoin’s dramatic swing from a peak of $124,000 to a low of $117,500 in mere hours has left…

crypto insight|2025/08/15 10:10:17
News thumbnail

First US Staked Crypto ETF Hits the Market Today on August 15, 2025, Delivering Solana Exposure and Staking Rewards

Imagine stepping into a new era where your investments in cryptocurrency not only track the price of a…

crypto insight|2025/08/15 10:10:18
News thumbnail

DOJ Indicts Four North Koreans for $1 Million Crypto Heist from Blockchain Firm on August 15, 2025

As of today, August 15, 2025, the crypto market shows Bitcoin trading at $58,320 with a 0.85% gain,…

crypto insight|2025/08/15 10:10:18
News thumbnail

US Senate Approves Trump’s Budget Bill, Skipping Key Crypto Tax Reforms on August 15, 2025

As of today, August 15, 2025, the landscape of cryptocurrency regulation in the United States continues to evolve,…

crypto insight|2025/08/15 10:10:18
Share
copy

Gainers

Community
iconiconiconiconiconiconicon

Customer Support@weikecs

Business Cooperation@weikecs

Quant Trading & MMbd@weex.com

VIP Servicessupport@weex.com