ChainCatcher message, SlowMist's Chief Information Security Officer 23pds forwarded a community user's tweet on the X platform showing that a developer of a Polymarket copy trading bot hid malicious code in the GitHub code. When the program is launched, it automatically reads the user's “.env” file (which contains the wallet Private Key) and then sends the Private Key to the hacker's server, leading to the theft of the Private Key and funds. The program's author repeatedly modifies and submits code on GitHub, deliberately hiding the malicious package. 23pds stated that we need to be vigilant about this method, “this is not the first time, nor will it be the last.”
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Slow Fog CISO: Beware of hidden malicious code in a certain Polymarket copy trading Bots program that steals Private Key
ChainCatcher message, SlowMist's Chief Information Security Officer 23pds forwarded a community user's tweet on the X platform showing that a developer of a Polymarket copy trading bot hid malicious code in the GitHub code. When the program is launched, it automatically reads the user's “.env” file (which contains the wallet Private Key) and then sends the Private Key to the hacker's server, leading to the theft of the Private Key and funds. The program's author repeatedly modifies and submits code on GitHub, deliberately hiding the malicious package. 23pds stated that we need to be vigilant about this method, “this is not the first time, nor will it be the last.”