SlowMist: GitHubs popular Solana tool hides a trap for stealing coins

By: odaily.com|2025/07/03 11:41:26
Share
copy

Odaily News According to the monitoring of the SlowMist security team, on July 2, a victim said that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of increasing the popularity of the project, the user ran the Node.js project with malicious dependencies without any defense, resulting in the leakage of wallet private keys and theft of assets. The entire attack chain involves multiple GitHub accounts to operate in coordination, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses social engineering and technical means, and it is difficult to fully defend within the organization. SlowMist recommends that developers and users be highly vigilant against GitHub projects of unknown origin, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.

You may also like

Key Market Intelligence as of December 31st, how much did you miss out on?

1. On-chain Volume: $69.3M USD flowed into Ethereum today; $59.5M USD flowed out of Arbitrum 2. Biggest Gainers and Losers: $OMNI, $BETA 3. Top News: LIGHT surged over 250% in the last 2 hours, breaking above $1.1

Long-standing domestic public blockchain NEO sees feud between two co-founders, with opaque finances as the core reason

Domestic AI projects are surging, while domestic public blockchains are bickering

Hong Kong Virtual Asset Trading Platform New Regulations (Part 2): New Circular Issued, Has the Boundary of Virtual Asset Business Been Redefined?

The market's potential to advance is now less about regulatory permissiveness and more about whether participants are truly ready to operate under a more transparent and rigorous ruleset.

DeFi 2.0 Explosion Post-Disorderly Restructuring in 2026

The further disordered reorganization of the macro environment, and the consequent drive toward the DeFi 2.0 explosion, both have clear trends and inevitability.

Fed's Latest Meeting Minutes: Divergence Persists, But "Most" Officials Advocate Continued Rate Cuts

Most participants support a rate cut in December, with a few indicating that this decision was finely balanced and they might have supported standing pat. Those in favor of a rate cut generally pointed to the increased downside risks to employment seen in recent months.

AI Trading in Crypto: How Traders Actually Apply AI in Real Crypto Markets

Artificial intelligence has moved beyond experimentation in crypto markets. In 2025, AI-driven trading tools are increasingly used by traders who want better discipline, faster execution, and more structured decision-making in volatile markets. This guide explains how AI is actually used in crypto trading, step by step — with a focus on how these strategies are executed in real trading environments.

Popular coins

Latest Crypto News

Read more