Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore

News

Stay up to date on the latest crypto trends with our expert, in-depth coverage.

banner
Flash
03:48
Security Alert: GitHub is experiencing an incident where a bot posing as a "follower" has been stealing private keys from malicious projects.
 GitHub project polymarket-copy-trading-bot has been injected with malicious code. The program automatically reads the wallet private key from the user's .env file upon startup and exfiltrates it to a hacker server through a hidden malicious dependency package [email protected], resulting in asset theft.
03:47
Security Alert: Malicious Projects Disguised as "Copy Trading Bots" on GitHub Stealing Private Keys
Jinse Finance reported that the GitHub project polymarket-copy-trading-bot has been implanted with malicious code. When the program is launched, it automatically reads the user's .env file for the wallet private key and transmits it to the hacker's server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.
03:41
SlowMist CISO: Beware of a certain Polymarket trading bot attempting to steal the private key
BlockBeats News, December 21st, SlowMist Chief Information Security Officer 23pds retweeted a community user's tweet to issue a security . A developer of a Polymarket copy-trading bot hid malicious code in the GitHub codebase. The bot would automatically read the user's '.env' file (containing the wallet private key) upon activation, leading to fund theft. The author of this bot repeatedly modified the code and made multiple code submissions on GitHub, intentionally concealing the malicious payload.
News
© 2025 Bitget