SlowMist: GitHubs popular Solana tool hides a trap for stealing coins

By: odaily.com|2025/07/03 11:41:20

Odaily News According to the monitoring of the SlowMist security team, on July 2, a victim said that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of increasing the popularity of the project, the user ran the Node.js project with malicious dependencies without any defense, resulting in the leakage of wallet private keys and theft of assets. The entire attack chain involves multiple GitHub accounts to operate in coordination, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses social engineering and technical means, and it is difficult to fully defend within the organization. SlowMist recommends that developers and users be highly vigilant against GitHub projects of unknown origin, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.

You may also like

WEEX Global Journey 2025: Connecting the World of Web3

WEEX Global Journey 2025: Connecting the World of Web3

WEEX’s H2 2025 global tour is hitting top blockchain stages and exclusive community meetups worldwide — connecting with real builders, sparking honest conversations, and creating lasting trust. Our mission: make trading simpler, confidence stronger, and crypto trusted across the globe.

WEEX|2025/08/08 08:04:07
News thumbnail

Almanak (ALMANAK) Coin ICO: A Hidden Gem Worth Exploring?

I’ve been diving deep into the crypto space for years now, and every so often, a project catches…

crypto insight|2025/08/08 09:10:17
News thumbnail

Emmet Finance (EMMET) IDO: Should You Jump In?

I’ve been digging into new DeFi projects lately, and one that caught my eye is the upcoming Emmet…

crypto insight|2025/08/08 09:10:17
News thumbnail

AfriCred (IFT) IDO: A Game-Changer for African SMEs?

I’ve been digging into promising crypto projects for years, and AfriCred (IFT) IDO caught my eye recently. I…

crypto insight|2025/08/08 08:30:17
News thumbnail

Suzaku Network (SUZ) IDO: A Hidden Gem Worth Watching

I’ve been digging through the latest IDOs, and I’ve gotta say, the Suzaku Network (SUZ) IDO caught my…

crypto insight|2025/08/08 08:10:17
Share
copy

Gainers

Community
iconiconiconiconiconiconiconicon

Customer Support@weikecs

Business Cooperation@weikecs

Quant Trading & MM[email protected]

VIP Services[email protected]