ChainCatcher message, SlowMist's Chief Information Security Officer 23pds forwarded a community user's tweet on the X platform showing that a developer of a Polymarket copy trading bot hid malicious code in the GitHub code. When the program is launched, it automatically reads the user's “.env” file (which contains the wallet Private Key) and then sends the Private Key to the hacker's server, leading to the theft of the Private Key and funds. The program's author repeatedly modifies and submits code on GitHub, deliberately hiding the malicious package. 23pds stated that we need to be vigilant about this method, “this is not the first time, nor will it be the last.”
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.