The Ethereum core developer's cryptocurrency Wallet was drained by a malicious AI extension.

robot
Abstract generation in progress

A core Ethereum developer stated that he was attacked by a cryptocurrency wallet drainer related to a fake encryption assistant, demonstrating that even veteran programmers can fall victim to increasingly sophisticated scams.

Zak Cole, an Ethereum developer, lost money due to installing a malicious AI extension from Cursor AI, which allowed the attacker to access his hot wallet for 3 days before draining the funds on August 10. The extension "contractshark.solidity-lang" looked legitimate with a professional icon, clear description, and over 54,000 downloads, but quietly extracted the private key from the .env file and sent it to the attacker's server.

Cole said he only lost a few hundred USD in ETH due to using a small hot wallet, separating it for testing and storing his main assets on a hardware wallet. Experts warn that fake extensions and VS Code are becoming major attack channels, advising to carefully check plugins, avoid storing keys in text form, and prioritize hardware wallets.

The Ethereum core developer's crypto wallet drained by malicious AI extension

ETH2.52%
CORE1.41%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)