Skip to main content

Threats Tagged 'solidity'

View all threats tagged with 'solidity'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: solidity

Threats Tagged 'solidity'

Click on any threat for detailed analysis and mitigation recommendations

A series of cryptocurrency scams have been uncovered where threat actors distribute malicious smart contracts disguised as trading bots to drain user wallets. The campaign has stolen over $900,000 US and employs multiple obfuscation techniques to conceal the attacker's wallet address. Leveraging aged YouTube accounts and curated comment sections, the scams create a false sense of legitimacy. The smart contracts, written in Solidity, use various methods to hide the attacker's Externally Owned Account. Distribution occurs through YouTube videos explaining the contracts as trading arbitrage bots, with some videos showing signs of being AI-generated. The most successful scam yielded approximately $902,000 US from a single attacker address.

Join the discussion

A blockchain developer in Russia lost $500,000 in crypto assets due to a malicious Solidity Language extension for Cursor AI IDE. The fake extension, downloaded 54,000 times, appeared higher in search results than the legitimate one due to ranking algorithms. It installed malware that allowed remote access and data theft. The attackers used ScreenConnect for remote control and deployed various scripts to steal wallet passphrases. A new malicious package was published shortly after the first was removed, with an inflated download count of 2 million. Similar attacks were found targeting blockchain developers through other extensions and npm packages. The incident highlights the ongoing threat of malicious open-source packages in the crypto industry.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: solidity
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses