Slow Fog CISO: Beware of hidden malicious code in a certain Polymarket copy trading Bots program that steals Private Key

ChainCatcher message, SlowMist's Chief Information Security Officer 23pds forwarded a community user's tweet on the X platform showing that a developer of a Polymarket copy trading bot hid malicious code in the GitHub code. When the program is launched, it automatically reads the user's “.env” file (which contains the wallet Private Key) and then sends the Private Key to the hacker's server, leading to the theft of the Private Key and funds. The program's author repeatedly modifies and submits code on GitHub, deliberately hiding the malicious package. 23pds stated that we need to be vigilant about this method, “this is not the first time, nor will it be the last.”

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)