Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Ethereum News

Ethereum Dev Zak.eth Hit by Malicious VS Code Extension Hack

How a Fake VS Code Extension Stole from an Ethereum Developer and Sparked a Wake-Up Call for Builder Security

Written By:
Kenrodgers Fabian

Reviewed By:
Jahnu Jagtap

Last updated: August 14, 2025 12:17 AM
Published 2025-08-13
Share
Ethereum Dev Zak.eth Hit by Malicious VS Code Extension Hack

A decade of flawless security ended for Ethereum core developer Zak.eth after a malicious VS Code extension on ai code editor Cursor drained his wallet. The incident, which occurred last week, involved the “contractshark.solidity-lang” extension. 

According to Zak.eth X thread, the extension appeared legitimate with over 54,000 downloads, a professional description, and presence in Cursor’s default registry. However, within minutes of installation, the extension accessed Zak’s .env file and transmitted his private key to an attacker’s server. Three days later, the attacker drained funds.

2/ The Attack Vector "contractshark.solidity-lang" extension in Cursor/VS Code.

Looked legitimate:
– Professional icon
– Proper description
– 54,000+ downloads
– From Open VSX (Cursor's default registry)
– Publisher "contractshark" seemed reasonable

— zak.eth (@0xzak) August 12, 2025

Zak lost only a few hundred dollars thanks to strict operational security. His main funds remained on hardware wallets. “If it can happen to me, it can happen to you,” he warned, noting he had never been hacked before. The attack is part of a larger $500,000+ theft campaign targeting developers through supply chain vulnerabilities.

How the Attack Unfolded

The extension exploited misspelt names, huge download counts, and confidence in official registries. By using only JavaScript, it was able to evade OS-level malware detection.

It primarily targeted developers who were rushing to release their work at the most vulnerable times. Zak acknowledged that he overlooked some warning signs, like the absence of a linked GitHub repository and the odd naming of the publisher.

In addition to losing money, he stumbled upon malicious tools used by the attacker, including “juanbIanco.solidity” and the “solsafe” npm package. He advised developers to conduct an immediate audit of their installed extensions, change their keys, and ensure that no sensitive information is left in their .env files.

Strengthening Developer Defenses

Following the breach, Zak redesigned his workflow. The developer uses isolated virtual machines, hardware wallets exclusively, and encrypted vaults for secrets. Also, he applies an extension whitelist and avoids installing new tools in haste.

Security experts echo his advice. Hakan Unal from Cyvers stressed, “Builders should vet extensions, avoid storing secrets in plain text or .env file, use hardware wallets, and develop in isolated environments.”

This breach shows that even the most security-conscious developers remain vulnerable to modern supply chain attacks. Consequently, developer trust in extension marketplaces is a side to be re-evaluated. As Zak concluded, “Good OpSec saved me from disaster. Paranoia paid off.”

Also Read: US, Allies Dismantle BlackSuit, Grab $1M in Crypto Assets

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Ethereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Jahnu Jagtap - Crypto Research Analyst at The Crypto Times
By Jahnu Jagtap
Follow:
Jahnu Jagtap is a Research Analyst with over 5 years of experience in crypto, finance, fintech, blockchain, Web3, and AI. He holds a BSc in Mathematics and is certified in Blockchain and Its Applications (SWAYAM MHRD), Cryptocurrency (Upskillist), and NISM Certifications. Jahnu specializes in technical, on-chain, and fundamental analysis, while also closely tracking global macro trends, regulations, lawsuits, and U.S. equities. With a strong analytical background and editorial insight, he drives content that delivers clarity and depth in the fast-evolving world of digital finance.

Latest News

Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ethereum Foundation Sees Another Exit as Hsiao-Wei Wang Steps Down
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Sen. Gillibrand's Son Bets on Perpetual Futures With $30M Raise
Sen. Gillibrand’s Son Bets on Perpetual Futures With $30M Raise

Find Us on Socials

You may also like

Crypto Market Crash BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Crypto Market Crash: BTC, ETH, XRP, SOL Drop 5%, Liquidations Hit $578M

Binance Users Added Ether More Than Twice as Fast as Bitcoin in May

Binance Users Added Ether More Than Twice as Fast as Bitcoin in May 2026

FOMC Decision Wipes Out $122M as BTC & ETH Liquidations Surge

FOMC Decision Wipes Out $122M as BTC & ETH Liquidations Surge

Zama Brings Confidential USDC Yield to Ethereum with Morpho

Zama Brings Confidential USDC Yield to Ethereum with Morpho

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information