Express
SlowMist CISO: Beware of Malicious Code in Polymarket Copy Trading Bot Program Stealing Private Keys
Summary: In a tweet, SlowMist Technology's Chief Information Security Officer 23pds shared that a developer of a Polymarket copy trading bot program has hidden malicious code in the GitHub code, which automatically reads users' ".env" files (containing wallet private keys), sends the private keys to a hacker server, and steals them, resulting in funds being stolen. ...
In a tweet, SlowMist Technology's Chief Information Security Officer 23pds shared that a developer of a Polymarket copy trading bot program has hidden malicious code in the GitHub code, which automatically reads users' ".env" files (containing wallet private keys), sends the private keys to a hacker server, and steals them, resulting in funds being stolen. The program's author has repeatedly modified and submitted code on GitHub, intentionally hiding the malicious package. 23pds warns to be cautious of this method, stating that it "is not the first time, nor will it be the last time".
Tags:
Link: SlowMist CISO: Beware of Malicious Code in Polymarket Copy Trading Bot Program Stealing Private Keys [Copy]