Slow Fog Cosine: The automation platform is indeed convenient, but users must have the ability to navigate it when using it
ChainCatcher news, Slow Mist founder Yu Xian posted on social media: "A few days ago, someone had their Atomicals asset ATOM stolen because some people were heavily promoting the use of the online programming platform Replit to run atomicals-js for automating operations related to Atomicals assets on the X platform.
Replit itself seems to be fine, and this kind of promotion also seems to be okay, but the problem lies in the openness of the Replit platform and the lack of security awareness among players. Anyone can see the atomicals-js you are using, including the mnemonic phrases/private keys/addresses you have configured. Thus, simple techniques like Google Hacking can discover these leaks, leading to asset theft.
It is important to note that while automation platforms or tools are indeed convenient, one must have the ability to handle them when using them. The impact here is not only on some players' Atomicals assets; we have also seen similar issues with inscription assets on other chains. Before we made this information public, such attacks had already occurred, and we have also connected with the relevant victims."