• bitcoinBitcoin (BTC) $ 67,584.00
  • ethereumEthereum (ETH) $ 1,975.84
  • tetherTether (USDT) $ 0.999858
  • bnbBNB (BNB) $ 629.16
  • xrpXRP (XRP) $ 1.36
  • usd-coinUSDC (USDC) $ 0.999994
  • solanaSolana (SOL) $ 84.84
  • tronTRON (TRX) $ 0.281474
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.090560
  • whitebitWhiteBIT Coin (WBT) $ 49.04
  • cardanoCardano (ADA) $ 0.265759
  • usdsUSDS (USDS) $ 0.999971
  • bitcoin-cashBitcoin Cash (BCH) $ 439.23
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 9.08
  • hyperliquidHyperliquid (HYPE) $ 32.25
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 342.51
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 8.74
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.999599
  • canton-networkCanton (CC) $ 0.157845
  • stellarStellar (XLM) $ 0.151647
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999386
  • rainRain (RAIN) $ 0.009246
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999788
  • paypal-usdPayPal USD (PYUSD) $ 0.999847
  • litecoinLitecoin (LTC) $ 53.90
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • hedera-hashgraphHedera (HBAR) $ 0.096182
  • avalanche-2Avalanche (AVAX) $ 9.07
  • zcashZcash (ZEC) $ 218.02
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.908188
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • crypto-com-chainCronos (CRO) $ 0.074846
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.23
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.105618
  • tether-goldTether Gold (XAUT) $ 5,160.81
  • polkadotPolkadot (DOT) $ 1.49
  • pax-goldPAX Gold (PAXG) $ 5,202.80
  • uniswapUniswap (UNI) $ 3.85
  • memecoreMemeCore (M) $ 1.38
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.663994
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • global-dollarGlobal Dollar (USDG) $ 0.999732
  • nearNEAR Protocol (NEAR) $ 1.35
  • falcon-financeFalcon USD (USDF) $ 0.996857
  • bittensorBittensor (TAO) $ 181.34
  • aster-2Aster (ASTER) $ 0.700272
  • aaveAave (AAVE) $ 112.39
  • pi-networkPi Network (PI) $ 0.170778
  • skySky (SKY) $ 0.069594
  • okbOKB (OKB) $ 76.11
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999893
  • bitget-tokenBitget Token (BGB) $ 2.13
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pepePepe (PEPE) $ 0.000003
  • bfusdBFUSD (BFUSD) $ 0.999592
  • internet-computerInternet Computer (ICP) $ 2.41
  • ethereum-classicEthereum Classic (ETC) $ 8.46
  • ondo-financeOndo (ONDO) $ 0.252620
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.00
  • worldcoin-wldWorldcoin (WLD) $ 0.395391
  • gatechain-tokenGate (GT) $ 6.96
  • pump-funPump.fun (PUMP) $ 0.001905
  • morphoMorpho (MORPHO) $ 1.98
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.099422
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • kucoin-sharesKuCoin (KCS) $ 7.63
  • midnight-3Midnight (NIGHT) $ 0.059915
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ethenaEthena (ENA) $ 0.110132
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.80
  • nexoNEXO (NEXO) $ 0.857821
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • usdtbUSDtb (USDTB) $ 1.00
  • hash-2Provenance Blockchain (HASH) $ 0.014928
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.030006
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • official-trumpOfficial Trump (TRUMP) $ 3.42
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • flare-networksFlare (FLR) $ 0.009129
  • algorandAlgorand (ALGO) $ 0.085871
  • wbnbWrapped BNB (WBNB) $ 759.61
  • filecoinFilecoin (FIL) $ 0.992865
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • ousgOUSG (OUSG) $ 114.46
  • aptosAptos (APT) $ 0.969044
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • usddUSDD (USDD) $ 0.999796
  • xdce-crowd-saleXDC Network (XDC) $ 0.035368
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • render-tokenRender (RENDER) $ 1.34
  • jupiter-exchange-solanaJupiter (JUP) $ 0.177466
  • stable-2​​Stable (STABLE) $ 0.029919
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • beldexBeldex (BDX) $ 0.080196
  • vechainVeChain (VET) $ 0.007120
  • arbitrumArbitrum (ARB) $ 0.100940
  • yldsYLDS (YLDS) $ 0.999940
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • usual-usdUsual USD (USD0) $ 0.993959
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • bonkBonk (BONK) $ 0.000006
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • decredDecred (DCR) $ 29.72
  • pippinpippin (PIPPIN) $ 0.495939
  • true-usdTrueUSD (TUSD) $ 0.999081
  • clbtcclBTC (CLBTC) $ 76,920.00
  • a7a5A7A5 (A7A5) $ 0.012518
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.752584
  • fasttokenFasttoken (FTN) $ 1.09
  • blockstackStacks (STX) $ 0.254833
  • euro-coinEURC (EURC) $ 1.16
  • usdaiUSDai (USDAI) $ 0.999556
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • sei-networkSei (SEI) $ 0.067074
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.34
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006951
  • justJUST (JST) $ 0.048683
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • dashDash (DASH) $ 33.62
  • kinesis-goldKinesis Gold (KAU) $ 167.25
  • tezosTezos (XTZ) $ 0.370679
  • power-protocolPower Protocol (POWER) $ 1.86
  • chilizChiliz (CHZ) $ 0.036921
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998770
  • layerzeroLayerZero (ZRO) $ 1.85
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • ether-fiEther.fi (ETHFI) $ 0.502341
  • curve-dao-tokenCurve DAO (CRV) $ 0.248371
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • c8ntinuumc8ntinuum (CTM) $ 0.081694
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • usxUSX (USX) $ 0.999869
  • cocaCOCA (COCA) $ 1.30
  • gnosisGnosis (GNO) $ 129.14
  • kite-2Kite (KITE) $ 0.188786
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.147803
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • hastra-primePRIME (PRIME) $ 1.02
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • apenftAINFT (NFT) $ 0.00000033
  • riverRiver (RIVER) $ 17.32
  • lighterLighter (LIT) $ 1.32
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • kaiaKaia (KAIA) $ 0.054438
  • mantra-daoMANTRA [Old] (OM) $ 0.066981
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • adi-tokenADI (ADI) $ 3.20
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • aerodrome-financeAerodrome Finance (AERO) $ 0.336693
  • sun-tokenSun Token (SUN) $ 0.015987
  • injective-protocolInjective (INJ) $ 3.03
  • venice-tokenVenice Token (VVV) $ 6.80
  • bitcoin-svBitcoin SV (BSV) $ 15.06
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • spx6900SPX6900 (SPX) $ 0.324335
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • story-2Story (IP) $ 0.847327
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • crvusdcrvUSD (CRVUSD) $ 0.999374
  • siren-2Siren (SIREN) $ 0.387348
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • celestiaCelestia (TIA) $ 0.319623
  • iotaIOTA (IOTA) $ 0.065600
  • the-graphThe Graph (GRT) $ 0.025763
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • fraxLegacy Frax Dollar (FRAX) $ 0.994437
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • olympusOlympus (OHM) $ 17.47
  • pyth-networkPyth Network (PYTH) $ 0.047469
  • jasmycoinJasmyCoin (JASMY) $ 0.005514
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • syrupMaple Finance (SYRUP) $ 0.235175
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • flokiFLOKI (FLOKI) $ 0.000028
  • optimismOptimism (OP) $ 0.124191
  • btse-tokenBTSE Token (BTSE) $ 1.58
  • lido-daoLido DAO (LDO) $ 0.303349
  • staked-aaveStaked Aave (STKAAVE) $ 126.65
  • plasmaPlasma (XPL) $ 0.111844

User Solana wallet exploited in first case of AI poisoning attack

0 109

User Solana wallet exploited in first case of AI poisoning attack

Methods of injecting malicious links are increasing, and it appears to have spread to even AI chat. In this case, the AI bot proposed scam API services, which led to user losses.

A user discovered ChatGPT is not as security conscious as they expected, especially with crypto links when they tried to create a simple crypto app, a token bumper for Pump.fun. The API link that ChatGPT provided was contaminated and led to an immediate loss.

The token bumper connected to the flawed API, which ended up demanding the wallet’s private key and siphoning all its assets. The incident serves as a timely reminder that artificial intelligence tools are not entirely reliable when it comes to Web3 security.

Be careful with information from @OpenAI ! Today I was trying to write a bump bot for https://t.co/cIAVsMwwFk and asked @ChatGPTapp to help me with the code. I got what I asked but I didn’t expect that chatGPT would recommend me a scam @solana API website. I lost around $2.5k ? pic.twitter.com/HGfGrwo3ir

— r_ocky.eth ? (@r_cky0) November 21, 2024

The fake API site has been busy with siphoning SOL from multiple wallets. The destination of the exploiter has already performed 281 transactions. While most of the sums were relatively small, all wallets used were compromised.

Rumors of AI poisoning attacks have been around for a while, but the recent attack is the first complete exploit in the crypto space.

The founder of the SlowMist on-chain security firm corroborated the story, stating that the most probable explanation was that the user was playing around with AI without verifying the code. The end product was a functional bot with a carefully disguised backdoor.

Fake Solana API attacks meme token traders

The exploiter used their API link to steal some of the latest meme tokens and store them in an identified known wallet. The haul included USDC, SOL, in addition to ELIZA, CHILLGIRL, and AI16Z.

The site also acted extremely fast after each connection. It is unknown who else made the call to the fake API site, which made its way into OpenAI’s data. One possible explanation is that ChatGPT accesses Python code from multiple repositories, which can be used to contaminate its available data. In the end, the intent to steal wallet data originates from a human agent. Artificial intelligence is only an amplification tool.

The code created by ChatGPT itself generated a part that asked for the private key. According to ScamSniffer, the exploiters deliberately seeded AI-generated Python code, which users would deploy to snipe new Pump.fun tokens.

Trusting the code was the first mistake, as users were quick to demand Moonshot or Pump.fun trading bots. Some of the repositories are still active, while others have been reported.

There is nothing to stop users from attempting to use the bots. The repositories of one such user, Solanaapisdev, still contain risky trading bots, which may end up draining wallets.

It is uncertain who created the bot, but the rush for meme tokens was enough to make unwitting users fall for these malicious trading bots. The best approach is to avoid using unknown repositories, or at least to review the code to the best of one’s knowledge.

Worse, the flawed APIs were also promoted in a Medium article, leading to a documentation page with the same name as the flawed GitHub repository. The available code is promoted to end users who want to automate the process on Jupiter, Raydium, Pump.fun, and Moonshot.

While some services can limit flawed links, there is little to do when end users have decided to risk their wallets with unverified code.

With more than 69K new meme tokens launched, the need and greed for speedy sniping has laid the foundation for a new type of exploit. OpenAI has not mentioned how ChatGPT was trained to create the risky bot code.

Malicious Zoom link scams also evolve

Another elaborate attack is evolving at the same time as the API exploit. The fake Zoom link that downloads malware has also changed.

The service, previously known as Meeten, is now spreading as Meetio, prompting users to download files. The malware also uses elements of social engineering, such as reaching out to crypto influencers, or known large-scale holders.

Recently, one of the fake Zoom meeting exploits drained an influencer’s wallet, leading to a crash in GIGA token prices.

The advice in each case is to store wallets and private keys on a different device than the one used for riskier connections. For token mints and other connections, the best approach is to use a newly assigned wallet.

A Step-By-Step System To Launching Your Web3 Career and Landing High-Paying Crypto Jobs in 90 Days.

Source

Leave A Reply

Your email address will not be published.