TechFlow news, December 21 — SlowMist's Chief Information Security Officer, 23pds, shared on X a community user's post indicating that the developer of a Polymarket copy-trading bot had hidden malicious code in the GitHub repository. When launched, the program automatically reads the user's ".env" file (which contains wallet private keys), then sends the private keys to a hacker-controlled server for theft. The author repeatedly modified and resubmitted the code on GitHub to deliberately conceal the malicious package. 23pds warned to be cautious of such attacks, stating, "It's not the first time, nor will it be the last."
Navigating Web3 tides with focused insights
Contribute An Article
Media Requests
Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / support@techflowpost.com ICP License: 琼ICP备2022009338号




