SlowMist: GitHubs popular Solana tool hides a trap for stealing coins

By: odaily.com|2025/07/03 11:41:20

Odaily News According to the monitoring of the SlowMist security team, on July 2, a victim said that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of increasing the popularity of the project, the user ran the Node.js project with malicious dependencies without any defense, resulting in the leakage of wallet private keys and theft of assets. The entire attack chain involves multiple GitHub accounts to operate in coordination, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses social engineering and technical means, and it is difficult to fully defend within the organization. SlowMist recommends that developers and users be highly vigilant against GitHub projects of unknown origin, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.

You may also like

WEEX Steals the Show at BlockchainRIO 2025: First LATAM Appearance Unlocks Brazil’s Crypto Potential

WEEX Steals the Show at BlockchainRIO 2025: First LATAM Appearance Unlocks Brazil’s Crypto Potential

In 2025, WEEX lit up Latin America with its debut at BlockchainRIO as Platinum Sponsor. With bold vision and unstoppable momentum, the rising exchange made waves across the region’s crypto scene.

WEEX|2025/08/13 09:30:52
News thumbnail

Zulu Network ZULU Coin Airdrop: How to Claim $500 Free Tokens by May 2025

I’ve been diving deep into cryptocurrency airdrops for years, and I still remember my first big win back…

crypto insight|2025/08/13 09:30:21
News thumbnail

Zypher Network Coin Airdrop: How to Claim Free Tokens Backed by $7M Funding by July 2025

I first stumbled upon Zypher Network last year while digging into ZK tech for a personal project, and…

crypto insight|2025/08/13 09:20:17
News thumbnail

Understanding Bitcoin CME Gaps: A Guide to Trading Them in 2025

Bitcoin CME gaps might sound like a mysterious puzzle in the crypto world, but they’re actually fascinating opportunities…

crypto insight|2025/08/13 06:40:15
News thumbnail

Crypto Payments and AI Fuel Massive Adoption Surge in 2025

As of today, August 13, 2025, the world of cryptocurrency continues to evolve rapidly, with fresh insights revealing…

crypto insight|2025/08/13 06:40:16
Share
copy

Gainers

Community
iconiconiconiconiconiconicon

Customer Support@weikecs

Business Cooperation@weikecs

Quant Trading & MMbd@weex.com

VIP Servicessupport@weex.com