• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M
Crypto Users Alerted: Solana Trading Bot Scam on GitHub

Crypto Users Alerted: Solana Trading Bot Scam on GitHub

user avatar

by Giorgi Kostiuk

3 hours ago


Cybersecurity firm SlowMist has issued a warning about a new type of crypto scam masquerading as a legitimate trading bot for Solana.

Innocent Bot With a Dangerous Twist

A user downloaded an open-source bot from GitHub, ran it, and soon after, their wallet was emptied. The project, called 'solana-pumpfun-bot,' appeared to be normal, boasting stars, forks, and even recent commits. However, it was a Node.js app with a hidden dependency – a package linked from a custom GitHub URL, allowing the malicious package to bypass NPM's security checks.

Faked Popularity on GitHub

To appear safe, the attacker used fake GitHub accounts to star and fork the project, giving it the semblance of wide usage. However, according to SlowMist, the entire codebase was uploaded just three weeks ago, indicating something was amiss. In a tweet, SlowMist stated, 'The perpetrator disguised a malicious program as a legit open-source project... users unknowingly ran a Node.js project with embedded malicious dependencies, exposing their private keys and losing assets.'

Important Warning for Devs and Traders

SlowMist advises users to never trust GitHub projects blindly, particularly those that require wallet access or deal with private keys. If you need to test such tools, it is advisable to do so in a sandboxed environment, avoiding real assets. The team warned, 'If you must test them, do so in a sandboxed, isolated environment with no sensitive data.'

As more traders and developers rely on open-source tools in crypto, such attacks are becoming harder to spot. The takeaway is simple: if a GitHub project deals with your wallet, treat it like it’s high-risk!

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

Neop and Bitcoin: Restoration of Freedom and Price Surge in Cryptocurrencies

chest

Neop completes his battle for decentralization while Bitcoin surpasses $109K with ETF gains.

user avatarGiorgi Kostiuk

New Promising Projects in Cryptocurrency: BlockDAG, Aptos, Polkadot, and Celestia

chest

Exploring four cryptocurrency projects that could become key players in the market by 2025.

user avatarGiorgi Kostiuk

Bitcoin Price Prediction: What to Expect in 2025?

chest

Bitcoin hit an all-time high in May 2025, but its position is becoming less stable amid geopolitical risks.

user avatarGiorgi Kostiuk

Mutuum Finance (MUTM) – A Promising Altcoin with a Unique Funding Model

chest

Mutuum Finance attracts investor interest with its unique DeFi model and successful presale. Learn about the project and its features.

user avatarGiorgi Kostiuk

Ondo Finance and Oasis Pro: New Collaboration in Tokenization

chest

Ondo Finance announces the acquisition of Oasis Pro, enhancing access to tokenized assets in the U.S. market.

user avatarGiorgi Kostiuk

Why JPMorgan Thinks Stablecoins Won’t Hit $1 Trillion Anytime Soon

chest

JPMorgan's analysis of the obstacles to stablecoin development amid growing interest in central bank digital currencies.

user avatarGiorgi Kostiuk
dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.