PANews reported on July 3 that according to the SlowMist security team, on July 2, a victim claimed that he had used an open source project hosted on GitHub thePANews reported on July 3 that according to the SlowMist security team, on July 2, a victim claimed that he had used an open source project hosted on GitHub the

SlowMist: GitHub's popular Solana tool hides a trap for stealing coins

2025/07/03 19:34

PANews reported on July 3 that according to the SlowMist security team, on July 2, a victim claimed that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of boosting the popularity of the project, the user ran the Node.js project with malicious dependencies without any precautions, resulting in the leakage of the wallet private key and the theft of assets. The entire attack chain involves the coordinated operation of multiple GitHub accounts, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses both social engineering and technical means, and it is difficult to fully defend against it within the organization.

SlowMist recommends that developers and users be highly vigilant against unknown GitHub projects, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.

Market Opportunity
OpenLedger Logo
OpenLedger Price(OPEN)
$0,17337
$0,17337$0,17337
+1,53%
USD
OpenLedger (OPEN) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Yarm Explained: Turning Trust and Tweets into Yield

Yarm Explained: Turning Trust and Tweets into Yield

tl;dr: Yarm is a new platform by Mitosis and Kaito AI that turns social influence into onchain yield. Yappers earn Mindshare by posting…Continue reading on Coinmonks »
Share
Medium2025/09/18 14:43
Crossmint Partners with MoneyGram for USDC Remittances in Colombia

Crossmint Partners with MoneyGram for USDC Remittances in Colombia

TLDR Crossmint enables MoneyGram’s new stablecoin payment app for cross-border transfers. The new app allows USDC transfers from the US to Colombia, boosting financial inclusion. MoneyGram offers USDC savings and Visa-linked spending for Colombian users. The collaboration simplifies cross-border payments with enterprise-grade blockchain tech. MoneyGram, a global leader in remittance services, launched its stablecoin-powered cross-border [...] The post Crossmint Partners with MoneyGram for USDC Remittances in Colombia appeared first on CoinCentral.
Share
Coincentral2025/09/18 21:02
US SEC suspends trading in shares of digital asset treasury firms QMMM and Smart Digital

US SEC suspends trading in shares of digital asset treasury firms QMMM and Smart Digital

PANews reported on September 30th that the U.S. Securities and Exchange Commission (SEC) has suspended trading in QMMM Holdings Ltd.'s stock after its share price surged nearly 1,000% in less than three weeks, according to Bloomberg. The SEC stated on Monday that recommendations to buy QMMM stock posted on social media by "unidentified individuals" may have manipulated its share price. Since QMMM announced earlier this month that it would establish a "diversified cryptocurrency treasury" with an initial investment of $100 million, targeting investments in Bitcoin, Ethereum, and Solana, its share price has surged 959%. The SEC stated that the trading suspension is a temporary measure and will end at 11:59 PM EST on October 10th. On Monday, the SEC also suspended trading in Smart Digital Group Ltd.'s shares for similar reasons. The suspension will also expire at 11:59 PM ET on October 10. The company announced last week that it would establish a "diversified cryptocurrency asset pool," focusing on digital assets like Bitcoin and Ethereum. Since the announcement, its stock price has fallen significantly.
Share
PANews2025/09/30 08:32