Scan to download
BTC $65,319.59 -4.12%
ETH $1,873.38 -5.24%
BNB $597.22 -3.84%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $540.84 -5.44%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%
BTC $65,319.59 -4.12%
ETH $1,873.38 -5.24%
BNB $597.22 -3.84%
XRP $1.42 -4.56%
SOL $81.67 -4.53%
TRX $0.2795 -0.47%
DOGE $0.0974 -3.83%
ADA $0.2735 -4.22%
BCH $540.84 -5.44%
LINK $8.64 -2.97%
HYPE $28.98 -1.81%
AAVE $122.61 -3.42%
SUI $0.9138 -6.63%
XLM $0.1605 -4.62%
ZEC $260.31 -8.86%

Slow Fog: Popular Solana Tool on GitHub Hides Cryptocurrency Theft Trap

2025-07-03 19:38:28
Collection

ChainCatcher news, according to the Slow Mist security team, on July 2, a victim reported that they used an open-source project hosted on GitHub ------ zldp2002/solana-pumpfun-bot the day before, and subsequently their crypto assets were stolen. After analysis by Slow Mist, it was found that in this attack, the attacker disguised themselves as a legitimate open-source project (solana-pumpfun-bot) to lure users into downloading and running malicious code. Under the guise of boosting the project's popularity, users unknowingly ran a Node.js project with malicious dependencies, leading to the leakage of wallet private keys and asset theft. The entire attack chain involved multiple GitHub accounts working in coordination, expanding the scope of dissemination and enhancing credibility, making it highly deceptive. At the same time, such attacks combine social engineering and technical means, making it difficult to completely defend against them within organizations.

Slow Mist advises developers and users to be highly vigilant about unknown GitHub projects, especially when it involves wallet or private key operations. If debugging is indeed necessary, it is recommended to run and debug in an isolated environment that does not contain sensitive data.

app_icon
ChainCatcher Building the Web3 world with innovations.