Connect with us

Hi, what are you looking for?

Ethereum core dev crypto wallet malicious ai extension
Ethereum core dev crypto wallet malicious ai extension

News

Ethereum Core Dev Falls Victim to Sophisticated AI-Powered Wallet Drainer

Even elite blockchain builders aren’t immune to scams. Ethereum core developer Zak Cole revealed he lost funds after installing a seemingly legitimate AI coding assistant that secretly stole his private key. The incident highlights the growing danger of malicious extensions — now a prime weapon for crypto thieves worldwide.

Not even the most experienced crypto builders are safe from the latest wave of sophisticated scams.

On Tuesday, Ethereum core developer Zak Cole shared on X that he had fallen victim to a malicious AI-based code assistant that drained funds from his hot wallet. The culprit? A Cursor AI extension disguised as a legitimate Solidity development tool.


The Trap That Looked Legit

The extension, named “contractshark.solidity-lang”, appeared professional, complete with a sleek icon, detailed description, and over 54,000 downloads. But beneath the surface, it was a carefully engineered trap.

Once installed, the extension silently read Cole’s .env file, extracted his private key, and transmitted it to an attacker’s server. The attacker then had three days of unrestricted access to Cole’s hot wallet before finally draining it on Sunday.

“In 10+ years, I have never lost a single wei to hackers,” Cole admitted. “Then I rushed to ship a contract last week.” Fortunately, he only lost a few hundred dollars in Ether thanks to his security practice of keeping hot wallets small and isolated for project testing, with primary holdings stored securely on hardware wallets.


A Rising Threat for Crypto Developers

Security experts warn this is not an isolated incident. Hakan Unal, senior security operations lead at Cyvers, described malicious extensions as a “major attack vector” for crypto builders.

These attacks often use:

  • Fake publishers
  • Typosquatting (slightly misspelled package names)
  • Hidden key-stealing code

Unal advises developers to vet every extension, avoid storing sensitive keys in plain text, use hardware wallets, and work in isolated environments.


Wallet Drainers: Now Available for Rent

The threat is growing not just in complexity but accessibility. According to an AMLBot report published in April, wallet drainer malware is now offered as software-as-a-service, with criminals renting them for as little as $100 in USDT.

These tools have already caused significant damage:

  • In September 2024, a fake WalletConnect app on Google Play ran for over five months, stealing more than $70,000 in crypto.
  • Many fake app reviews mentioned irrelevant features—likely meant to fool unsuspecting users.

With scams becoming polished, professional, and cheap to deploy, experts say the risk to developers and investors alike has never been higher.

author avatar
Alex
Formally freelance blogger Alex is passionate writer with interest in Finance and Business, fascinated about crypto following news and covering stories.
Advertisement

You May Also Like

Alpha Zone

In his latest market breakdown, 360Trader sounds the alarm on a brewing altcoin shakeout that could catch traders off guard. From liquidity traps to...

Alpha Zone

Prepare for explosive growth: AI-native modular blockchain networks like Ritual and Bittensor are capturing VC dollars—and solving compute, trust, and on-chain AI training at...

Business

Ripple Labs and the U.S. Securities and Exchange Commission (SEC) have reached a landmark settlement after a years-long legal battle. The SEC agreed to...

Business

New York regulators have fined Paxos $48.5 million for anti-money laundering (AML) failures. These failures were part of a sweeping enforcement action linked to...

polkadot
Polkadot (DOT) $ 4.21 1.44%
bitcoin
Bitcoin (BTC) $ 120,943.00 0.32%
ethereum
Ethereum (ETH) $ 4,727.85 0.64%
cardano
Cardano (ADA) $ 0.968265 10.17%
xrp
XRP (XRP) $ 3.23 1.90%
stellar
Stellar (XLM) $ 0.443008 2.54%
litecoin
Litecoin (LTC) $ 127.81 2.70%