• bitcoinBitcoin (BTC) $ 69,467.00
  • ethereumEthereum (ETH) $ 2,148.18
  • tetherTether (USDT) $ 0.999902
  • xrpXRP (XRP) $ 1.35
  • bnbBNB (BNB) $ 604.58
  • usd-coinUSDC (USDC) $ 0.999764
  • solanaSolana (SOL) $ 82.31
  • tronTRON (TRX) $ 0.318279
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.092957
  • usdsUSDS (USDS) $ 1.00
  • whitebitWhiteBIT Coin (WBT) $ 52.52
  • cardanoCardano (ADA) $ 0.255521
  • leo-tokenLEO Token (LEO) $ 10.12
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • hyperliquidHyperliquid (HYPE) $ 37.08
  • bitcoin-cashBitcoin Cash (BCH) $ 439.54
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 9.04
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 329.32
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999617
  • stellarStellar (XLM) $ 0.162383
  • canton-networkCanton (CC) $ 0.139476
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • memecoreMemeCore (M) $ 2.72
  • daiDai (DAI) $ 0.999926
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.999964
  • zcashZcash (ZEC) $ 255.04
  • litecoinLitecoin (LTC) $ 54.34
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.44
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • hedera-hashgraphHedera (HBAR) $ 0.089495
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.908163
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.006577
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 325.20
  • the-open-networkToncoin (TON) $ 1.26
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.100240
  • crypto-com-chainCronos (CRO) $ 0.070440
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,635.35
  • pax-goldPAX Gold (PAXG) $ 4,654.44
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.672257
  • polkadotPolkadot (DOT) $ 1.31
  • uniswapUniswap (UNI) $ 3.20
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • skySky (SKY) $ 0.075841
  • okbOKB (OKB) $ 83.35
  • falcon-financeFalcon USD (USDF) $ 0.997794
  • pi-networkPi Network (PI) $ 0.171588
  • nearNEAR Protocol (NEAR) $ 1.30
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.669617
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • usddUSDD (USDD) $ 0.999268
  • pepePepe (PEPE) $ 0.000004
  • aaveAave (AAVE) $ 96.85
  • ripple-usdRipple USD (RLUSD) $ 0.999913
  • ethereum-classicEthereum Classic (ETC) $ 8.70
  • bfusdBFUSD (BFUSD) $ 0.999500
  • bitget-tokenBitget Token (BGB) $ 1.88
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • internet-computerInternet Computer (ICP) $ 2.37
  • ondo-financeOndo (ONDO) $ 0.267705
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • gatechain-tokenGate (GT) $ 6.52
  • algorandAlgorand (ALGO) $ 0.125786
  • kucoin-sharesKuCoin (KCS) $ 8.21
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 75.06
  • pump-funPump.fun (PUMP) $ 0.001743
  • render-tokenRender (RENDER) $ 1.96
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.04
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.093559
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • cosmosCosmos Hub (ATOM) $ 1.75
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • nexoNEXO (NEXO) $ 0.868051
  • usdtbUSDtb (USDTB) $ 0.998038
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.031421
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • morphoMorpho (MORPHO) $ 1.54
  • worldcoin-wldWorldcoin (WLD) $ 0.253134
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.082862
  • aptosAptos (APT) $ 0.877943
  • wbnbWrapped BNB (WBNB) $ 759.61
  • midnight-3Midnight (NIGHT) $ 0.041883
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • filecoinFilecoin (FIL) $ 0.902013
  • official-trumpOfficial Trump (TRUMP) $ 2.91
  • ousgOUSG (OUSG) $ 114.79
  • flare-networksFlare (FLR) $ 0.007517
  • vechainVeChain (VET) $ 0.007479
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • hash-2Provenance Blockchain (HASH) $ 0.011152
  • xdce-crowd-saleXDC Network (XDC) $ 0.031510
  • yldsYLDS (YLDS) $ 0.999932
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • beldexBeldex (BDX) $ 0.079612
  • arbitrumArbitrum (ARB) $ 0.098654
  • jupiter-exchange-solanaJupiter (JUP) $ 0.165759
  • ghoGHO (GHO) $ 0.999630
  • stable-2​​Stable (STABLE) $ 0.026866
  • justJUST (JST) $ 0.063976
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.996635
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.238223
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000006
  • true-usdTrueUSD (TUSD) $ 0.999215
  • layerzeroLayerZero (ZRO) $ 1.92
  • clbtcclBTC (CLBTC) $ 76,920.00
  • a7a5A7A5 (A7A5) $ 0.012330
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.44
  • siren-2Siren (SIREN) $ 0.599635
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.657029
  • euro-coinEURC (EURC) $ 1.15
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006581
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • blockstackStacks (STX) $ 0.224195
  • chilizChiliz (CHZ) $ 0.039234
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • dexeDeXe (DEXE) $ 8.55
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • dashDash (DASH) $ 31.20
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999550
  • tezosTezos (XTZ) $ 0.354224
  • sei-networkSei (SEI) $ 0.054704
  • hastra-primePRIME (PRIME) $ 1.03
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • decredDecred (DCR) $ 20.65
  • adi-tokenADI (ADI) $ 4.46
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • kinesis-goldKinesis Gold (KAU) $ 149.73
  • usxUSX (USX) $ 0.999938
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • ether-fiEther.fi (ETHFI) $ 0.451825
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017382
  • cocaCOCA (COCA) $ 1.30
  • curve-dao-tokenCurve DAO (CRV) $ 0.218192
  • apenftAINFT (NFT) $ 0.00000033
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • gnosisGnosis (GNO) $ 122.93
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • venice-tokenVenice Token (VVV) $ 7.08
  • monadMonad (MON) $ 0.029284
  • bitcoin-svBitcoin SV (BSV) $ 15.89
  • edgexedgeX (EDGE) $ 0.898205
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • bittorrentBitTorrent (BTT) $ 0.00000031
  • plasmaPlasma (XPL) $ 0.125233
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • aerodrome-financeAerodrome Finance (AERO) $ 0.319675
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • injective-protocolInjective (INJ) $ 2.95
  • doublezeroDoubleZero (2Z) $ 0.082496
  • kaiaKaia (KAIA) $ 0.047866
  • kinesis-silverKinesis Silver (KAG) $ 73.18
  • lido-daoLido DAO (LDO) $ 0.324908
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • conflux-tokenConflux (CFX) $ 0.052769
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • fraxLegacy Frax Dollar (FRAX) $ 0.993500
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • spx6900SPX6900 (SPX) $ 0.291785
  • usdaiUSDai (USDAI) $ 0.999834
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • flokiFLOKI (FLOKI) $ 0.000028
  • celestiaCelestia (TIA) $ 0.298835
  • official-foOfficial FO (FO) $ 0.268343
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • jasmycoinJasmyCoin (JASMY) $ 0.005391
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • zebec-networkZebec Network (ZBCN) $ 0.002713
  • the-graphThe Graph (GRT) $ 0.024552
  • crvusdcrvUSD (CRVUSD) $ 0.994277
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • lighterLighter (LIT) $ 1.05
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • iotaIOTA (IOTA) $ 0.059151

SlowMist discovers malicious code in GitHub’s ‘Solana-pumpfun-bot’

0 111

SlowMist discovers malicious code in GitHub’s 'Solana-pumpfun-bot'

SlowMist has brought to light that the widely used open-source project “Solana-pumpfun-bot” on the GitHub platform has code that steals crypto from its users’ wallets.

The investigation began on July 2, 2025. A victim contacted the SlowMist security team to seek assistance in analyzing the reasons for the theft of his wallet assets.

The incident was caused by his use of an open-source project hosted on GitHub the day before, where the encrypted assets were stolen. SlowMist states that stolen funds are being transferred to the FixedFloat exchange.

The project author is the main suspect

To pull the attack off, the hacker pretended to be an official open-source project (solana-pumpfun-bot) to get people to download and run malicious code. A suspicious dependent package named “crypto-layout-utils” was found to have been removed from the official NPM source throughout the inquiry.

The hacker subsequently uploaded a malicious version of the software in place of the original download URL. It sent sensitive data to an attacker-controlled server after searching the victim’s PC for wallet-related files.

The investigation also found that the project author is suspected of controlling multiple GitHub accounts. They were used to fork malicious projects, distribute malicious programs, and artificially inflate the project’s popularity. Multiple fork projects with similar malicious behavior were identified, some of which used another malicious package, “bs58-encrypt-utils”.

The entire attack chain involves several GitHub accounts working together. This expanded the scope of dissemination, enhanced credibility, and is extremely deceptive. At the same time, this attack used both social engineering and technical means, and it is difficult to defend against it fully within an organization.

The malicious activity is believed to have started on June 12, 2025. This is when the attacker created the malicious package “bs58-encrypt-utils”.

Crypto hacking hasn’t advanced much; they’ve become more cunning

According to Slowmist, crypto hacking techniques haven’t advanced much, but they’ve become far more cunning. SlowMist’s head of operations, Lisa, said in the firm’s Q2 MistTrack Stolen Fund Analysis report that although it didn’t see an advancement in hacking techniques, the scams have become more sophisticated.

There is a rise in fake browser extensions, tampered hardware wallets, and social engineering attacks. “We’re seeing a clear shift from purely on-chain attacks to off-chain entry points — browser extensions, social media accounts, authentication flows, and user behavior are all becoming common attack surfaces,” said Lisa.

Causes of theft in Q2 of 2025 | Source: SlowMist

For instance, attackers guide users to visit well-known, commonly used websites like Notion or Zoom. When the user attempts to download software from these official sites, the files delivered have already been maliciously replaced.

Another way is when hackers send users a compromised cold wallet. They tell their victims they have won a free device under a “lottery draw” or tell them their existing device was compromised and they needed to transfer their assets. Even better, hackers have introduced fake websites.

The final hit is usually manipulation. “Attackers know phrases like ‘risky signature detected’ can trigger panic, prompting users to take hasty actions. Once that emotional state is triggered, it’s much easier to manipulate them into doing things they normally wouldn’t — like clicking links or sharing sensitive information,” Lisa said.

Other attacks used hacking methods that took advantage of EIP-7702, which was added in the most recent version of Ethereum Pectra. Another attack took over the accounts of several WeChat users and targeted them. According to SlowMist, Ethereum led all ecosystems in security losses in the first half of 2025, with DeFi platforms losing around $470 million.

Source

Leave A Reply

Your email address will not be published.