Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Ethereum News

Ethereum Dev Zak.eth Hit by Malicious VS Code Extension Hack

How a Fake VS Code Extension Stole from an Ethereum Developer and Sparked a Wake-Up Call for Builder Security

Written By:
Kenrodgers Fabian

Reviewed By:
Jahnu Jagtap

Last updated: August 14, 2025 12:17 AM
Published August 13, 2025 10:38 PM
Share
Last updated: August 14, 2025 12:17 AM
Published August 13, 2025 10:38 PM
Ethereum Dev Zak.eth Hit by Malicious VS Code Extension Hack

A decade of flawless security ended for Ethereum core developer Zak.eth after a malicious VS Code extension on ai code editor Cursor drained his wallet. The incident, which occurred last week, involved the “contractshark.solidity-lang” extension. 

According to Zak.eth X thread, the extension appeared legitimate with over 54,000 downloads, a professional description, and presence in Cursor’s default registry. However, within minutes of installation, the extension accessed Zak’s .env file and transmitted his private key to an attacker’s server. Three days later, the attacker drained funds.

2/ The Attack Vector "contractshark.solidity-lang" extension in Cursor/VS Code.

Looked legitimate:
– Professional icon
– Proper description
– 54,000+ downloads
– From Open VSX (Cursor's default registry)
– Publisher "contractshark" seemed reasonable

— zak.eth (@0xzak) August 12, 2025

Zak lost only a few hundred dollars thanks to strict operational security. His main funds remained on hardware wallets. “If it can happen to me, it can happen to you,” he warned, noting he had never been hacked before. The attack is part of a larger $500,000+ theft campaign targeting developers through supply chain vulnerabilities.

How the Attack Unfolded

The extension exploited misspelt names, huge download counts, and confidence in official registries. By using only JavaScript, it was able to evade OS-level malware detection.

It primarily targeted developers who were rushing to release their work at the most vulnerable times. Zak acknowledged that he overlooked some warning signs, like the absence of a linked GitHub repository and the odd naming of the publisher.

In addition to losing money, he stumbled upon malicious tools used by the attacker, including “juanbIanco.solidity” and the “solsafe” npm package. He advised developers to conduct an immediate audit of their installed extensions, change their keys, and ensure that no sensitive information is left in their .env files.

Strengthening Developer Defenses

Following the breach, Zak redesigned his workflow. The developer uses isolated virtual machines, hardware wallets exclusively, and encrypted vaults for secrets. Also, he applies an extension whitelist and avoids installing new tools in haste.

Security experts echo his advice. Hakan Unal from Cyvers stressed, “Builders should vet extensions, avoid storing secrets in plain text or .env file, use hardware wallets, and develop in isolated environments.”

This breach shows that even the most security-conscious developers remain vulnerable to modern supply chain attacks. Consequently, developer trust in extension marketplaces is a side to be re-evaluated. As Zak concluded, “Good OpSec saved me from disaster. Paranoia paid off.”

Also Read: US, Allies Dismantle BlackSuit, Grab $1M in Crypto Assets

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Ethereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Jahnu Jagtap - Crypto Research Analyst at The Crypto Times
By Jahnu Jagtap
Follow:

Jahnu Jagtap is a Research Analyst with over 5 years of experience in crypto, finance, fintech, blockchain, Web3, and AI. He holds a BSc in Mathematics and is certified in Blockchain and Its Applications (SWAYAM MHRD), Cryptocurrency (Upskillist), and NISM Certifications. Jahnu specializes in technical, on-chain, and fundamental analysis, while also closely tracking global macro trends, regulations, lawsuits, and U.S. equities. With a strong analytical background and editorial insight, he drives content that delivers clarity and depth in the fast-evolving world of digital finance.

Latest News

India’s ED Widens ₹2,200 Cr HPZ Scam Probe, Uncovers Cross-Border Links
India’s ED Widens ₹2,200 Cr HPZ Scam Probe, Uncovers Cross-Border Links
MEGA Token Goes Live With $1.6B FDV Across Major Exchanges
MEGA Token Goes Live With $1.6B FDV Across Major Exchanges
Senate Closes the Door on Prediction Market Participation for Lawmakers
Senate Closes the Door on Prediction Market Participation for Lawmakers
uropean Asset Managers Discuss CLARITY Act With SEC Crypto Task Force
European Asset Managers Discuss CLARITY Act With SEC Crypto Task Force
Elon Musk Takes Aim at Crypto During OpenAI Showdown
Elon Musk Takes Aim at Crypto During OpenAI Showdown

Find Us on Socials

You may also like

Crypto Market Today: BTC, ETH, XRP, Slide as ETF Outflows Deepen

Crypto Market Today: BTC, ETH, XRP, Slide as ETF Outflows Deepen

Wasabi Protocol Hack Drains $5M Across Ethereum, Base, and Blast

Wasabi Protocol Hack Drains $5M Across Ethereum, Base, and Blast

Kyber Exploiter Actively Moves Stolen ETH via Tornado Cash

Kyber Exploiter Actively Moves Stolen ETH via Tornado Cash

EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool

EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information