Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    From Demonetization to Digital Rupee India's Decade-Long Blockchain Journey
    From Demonetization to Digital Rupee: India’s Decade-Long Blockchain Journey
    The 7% Premium Trap Exposed How India Makes Crypto More Expensive Than Dollars
    The 7% Premium Trap Exposed: How India Makes Crypto More Expensive Than Dollars
    GENIUS Act Scorecard What US Regulators Have Done So Far
    GENIUS Act Scorecard: What US Regulators Have Actually Delivered
    The Final 30 Days Will America Get Its GENIUS Act Stablecoin Rulebook
    The Final 30 Days: Will America Get Its GENIUS Act Stablecoin Rulebook?
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Crypto Stealing Solana Trading Bot on GitHub Exposed

Written By:
Jalpa Bhavsar

Reviewed By:
Kritika Mehta

Last updated: July 5, 2025 12:11 AM
Published 2025-07-04
Share
Crypto Stealing Solana Trading Bot on GitHub Exposed

A GitHub page pretending to be a real Solana trading bot was found to be hiding malware that steals crypto. The page was created by a user named “zldp2002” and looked like a real open-source tool. But when users ran it, their crypto got stolen.

The problem came to light after someone lost their funds. Blockchain security firm SlowMist looked into it and found the bot used strange coding patterns and had many fake stars and forks on GitHub to look trustworthy. For further context, all the code was uploaded around three weeks ago.

SlowMist found that the trading bot was built using Node.js and included a package named crypto-layout-utils. This package was already removed from the official Node.js (NPM) registry. Instead of using the official source, the attacker had users download it from a different GitHub page. This raised further suspicion.

When SlowMist experts scanned the package, they detected that it was highly obfuscated (made difficult on purpose) via a jsjiami.com webpage. Upon decoding, they discovered that the package scanned users’ local files. If it detected any wallet-related information or private keys, it would silently send the information to a remote server operated by the attacker.

The analysis also indicated that this was not the only malicious project. The hacker probably had multiple GitHub accounts for publishing similar spoofed projects. These projects were copied (forked) from actual ones and slightly modified to contain malware. Some used another malicious package named bs58-encrypt-utils-1.0.3, which was first introduced on June 12.

This case is part of a larger wave of cyberattacks on crypto users. Recently, hackers also targeted Firefox users with fake wallet extensions and used GitHub to spread harmful code.

Also Read: Solana Fosters New-Age Finance with Moody’s Onchain Credit Ratings

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Solana (SOL)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Jalpa Bhavsar- Senior crypto journalist at The Crypto Times
By Jalpa Bhavsar
Follow:
Jalpa Bhavsar is a Crypto Journalist with 3 years of experience in crypto, blockchain, AI, digital design, and crypto news reporting. She holds a B.Tech in Computer Science, bringing a strong technical foundation to her writing. Jalpa focuses on delivering clear, accurate, and engaging coverage of the latest trends and developments in the crypto and tech space.
Kritika Mehta- Former Sub Editor at The Crypto Times
By Kritika Mehta
Follow:
Kritika Mehta is a Sub Editor with over 4 years of experience in news writing, crypto news sourcing, editing, and covering topics across fintech and the stock market. She holds a BA in Journalism and Mass Communication and is certified in Multimedia Journalism. Kritika combines editorial precision with a sharp news sense to ensure content is accurate, engaging, and timely.

Latest News

PancakeSwap Labubu Pool Exploited for $1.1M
PancakeSwap Labubu Pool Exploited for $1.1M: What Went Wrong
How a Custom Code Flaw Cost Secret Network $4.67 Million
How a Custom Code Flaw Cost Secret Network $4.67 Million
Weaponizing Web3 Congress Pivots Crypto Policy Toward National Security
Weaponizing Web3: Congress Pivots Crypto Policy Toward National Security
Chervinsky Says CME's CFTC Lawsuit Backfired, Exposing a 'Monopolist'
Chervinsky Says CME’s CFTC Lawsuit Backfired, Exposing a ‘Monopolist’
CZ Predicts Crypto and TradFi Will Eventually Merge Into One Industry
CZ Predicts Crypto and TradFi Will Eventually Merge Into One Industry

Find Us on Socials

You may also like

Prediction Markets Hit Record $10.8B Weekly Volume Record on Global Events

Prediction Markets Hit Record $10.8B Weekly Volume Record on Global Events

Philippine SEC Explores RWA Tokenization for Overseas Filipino Workers

Philippine SEC Explores RWA Tokenization for Overseas Filipino Workers

Venus Protocol Launches Tokenized U.S. Stock Lending on BNB Chain

Venus Protocol Launches Tokenized U.S. Stock Lending on BNB Chain

Jio’s Mega IPO Filed How This Could Spark India's Mainstream Crypto Boom

Jio’s Mega IPO Filed: How This Could Spark India’s Mainstream Crypto Boom

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information