Express

SlowMist Reports Serious Vulnerabilities in NOFX AI Automated Trading System, Urges Immediate Upgrade

Summary: The SlowMist security team recently analyzed the open-source automated futures trading system NOFX AI based on DeepSeek/Qwen and discovered multiple serious authentication vulnerabilities. They pointed out that the system has a 'zero authentication' mode in the default configuration, with the admin mode directly enabled, allowing all requests to pass without verification, enabling attackers to access ...

The SlowMist security team recently analyzed the open-source automated futures trading system NOFX AI based on DeepSeek/Qwen and discovered multiple serious authentication vulnerabilities. They pointed out that the system has a 'zero authentication' mode in the default configuration, with the admin mode directly enabled, allowing all requests to pass without verification, enabling attackers to access /api/exchanges and obtain complete API keys and private keys. Although JWT is added in the 'authorization required' mode, the default jwt_secret still exists, and if environment variables are not set, it will revert to the default key. In addition, sensitive fields are still output in the original JSON format in this mode, which can lead to key leakage if the token is forged or stolen. SlowMist stated that by mid-November, they had identified over a thousand publicly deployed instances using vulnerable configurations and had coordinated with the security teams of Binance and OKEx to complete the relevant credential replacement. The team reminds all users to upgrade the system immediately, especially users running robots on Aster or Hyperliquid should check their settings as soon as possible.

Last Update:

Tags:
Link: SlowMist Reports Serious Vulnerabilities in NOFX AI Automated Trading System, Urges Immediate Upgrade   [Copy]
  • The Road to 2026: Where Is the Web3 Ecosystem Heading Next? 19 days ago
  • Vishwa Advances Agentic Infrastructure Research Through Contribution to Emerging Framew... November 22, 2025
  • BitMart US Launches Operations with 49-State Licensing and Zero-Fee Program November 17, 2025
  • Global Financial Giants Enter Stablecoin Arena in Pivotal Shift October 30, 2025
  • CRYPTO'S NEW PLAY: 24/7 STOCK TRADING October 29, 2025
  • You need to login to comment.