Scan to download
BTC $92,494.98 -0.08%
ETH $3,190.47 -0.54%
BNB $928.80 +0.90%
XRP $1.97 +0.48%
SOL $133.85 +0.07%
TRX $0.3101 -2.26%
DOGE $0.1285 +1.09%
ADA $0.3679 +0.98%
BCH $581.01 -1.44%
LINK $12.87 +0.14%
HYPE $23.70 -1.05%
AAVE $163.84 +0.34%
SUI $1.56 -1.67%
XLM $0.2155 +1.16%
ZEC $364.34 +0.36%
BTC $92,494.98 -0.08%
ETH $3,190.47 -0.54%
BNB $928.80 +0.90%
XRP $1.97 +0.48%
SOL $133.85 +0.07%
TRX $0.3101 -2.26%
DOGE $0.1285 +1.09%
ADA $0.3679 +0.98%
BCH $581.01 -1.44%
LINK $12.87 +0.14%
HYPE $23.70 -1.05%
AAVE $163.84 +0.34%
SUI $1.56 -1.67%
XLM $0.2155 +1.16%
ZEC $364.34 +0.36%

Slow Fog claims NOFX AI automatic trading system has a serious vulnerability that needs to be upgraded as soon as possible

2025-11-17 18:12:54
Collection

The Slow Mist security team recently analyzed the open-source automated futures trading system NOFX AI based on DeepSeek/Qwen and discovered multiple serious authentication vulnerabilities. They pointed out that the system has a "zero authentication" mode under default configuration, with administrator mode directly enabled, allowing all requests to pass without verification. Attackers can access /api/exchanges and obtain complete API keys and private keys. Although JWT has been added in the "authorization required" mode, the default jwt_secret still exists, and if the environment variable is not set, it will revert to the default key. Furthermore, in this mode, sensitive fields are still output in raw JSON, meaning that if the token is forged or stolen, it can also lead to key leakage.

Slow Mist stated that as of now, they have identified over a thousand publicly deployed instances using vulnerable configurations and have coordinated with the security teams of Binance and OKX to complete the relevant credential replacements. The team urges all users to upgrade their systems immediately, especially those running robots on Aster or Hyperliquid should check their settings as soon as possible.

ChainCatcher reminds readers to view blockchain rationally, enhance risk awareness, and be cautious of various virtual token issuances and speculations. All content on this site is solely market information or related party opinions, and does not constitute any form of investment advice. If you find sensitive information in the content, please click "Report", and we will handle it promptly.
app_icon
ChainCatcher Building the Web3 world with innovations.