• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Crypto Bot on GitHub Steals Wallets—Hundreds Fooled by Fake Solana Tool

user avatar

by Giorgi Kostiuk

4 hours ago


A recent cryptocurrency scam on GitHub has revealed the dangers associated with open-source projects. A bot posing as a Solana trading tool has stolen funds from unsuspecting users.

Background of the Scam

The project titled *solana-pumpfun-bot*, hosted under the account *zldp2002*, mimicked a legitimate tool but secretly harvested users' private information.

According to cybersecurity firm SlowMist, a victim contacted their team after losing crypto funds. Analysis of the code revealed malicious components aimed at sending private keys to an external server controlled by the hacker.

False Popularity Signals

In addition to its apparent legitimacy, the repository exhibited signs of manipulated popularity. It boasted over 400 forks and hundreds of stars, creating an impression of a trusted tool. These indicators misled many users into downloading the bot and running it without examining the source code.

SlowMist's research highlighted obfuscated JavaScript performing background operations on private keys and submitting data to a server controlled by the hacker.

Consequences and Recommendations

Experts emphasize the growing risks in open-source cryptocurrency development. SlowMist strongly advises users against relying on any metrics or appearances displayed in public repositories. When testing crypto tools, users should continuously conduct manual code audits and isolate third-party scripts. Incidents like this wallet-stealing bot underscore the necessity for careful verification of tools before connecting wallets or executing transactions.

This incident serves as a reminder of the risks associated with using open-source code in the crypto space. Users should exercise caution and carry out independent verifications of tools to avoid the theft of funds.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Analyst Rekt Capital Predicts Bitcoin Bull Market Will Conclude in a Few Months

chest

Analyst Rekt Capital suggests that Bitcoin's bull market could end in October. This has triggered a variety of opinions among experts.

user avatarGiorgi Kostiuk

Hong Kong Launches Stablecoin Licensing System to Strengthen Oversight

chest

Hong Kong introduces a stablecoin licensing system, marking significant changes in digital asset regulation.

user avatarGiorgi Kostiuk

XRP Market: Breakout Level and Uncertainty - What Are the Next Prospects?

chest

Analysis of the current XRP price situation: channel breakout, mixed indicator signals, and future movement forecasts.

user avatarGiorgi Kostiuk

Europe Must Embrace Stablecoins to Counter U.S. Dominance

chest

Lorenzo Bini Smaghi emphasizes the need for stablecoin adoption in Europe to enhance competitiveness.

user avatarGiorgi Kostiuk

Tradetomato Shares Achievements and Plans for Summer

chest

Tradetomato announces significant platform updates and market outlook.

user avatarGiorgi Kostiuk

Bitcoin Value Decline and Its Impact on Altcoins: What’s Next?

chest

The recent drop in Bitcoin to $107,800 raises concerns among traders, while the altcoin market remains stagnant.

user avatarGiorgi Kostiuk
dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.