Connect with us

Hi, what are you looking for?

Ethereum core dev crypto wallet malicious ai extension
Ethereum core dev crypto wallet malicious ai extension

News

Ethereum Core Dev Falls Victim to Sophisticated AI-Powered Wallet Drainer

Even elite blockchain builders aren’t immune to scams. Ethereum core developer Zak Cole revealed he lost funds after installing a seemingly legitimate AI coding assistant that secretly stole his private key. The incident highlights the growing danger of malicious extensions — now a prime weapon for crypto thieves worldwide.

Not even the most experienced crypto builders are safe from the latest wave of sophisticated scams.

On Tuesday, Ethereum core developer Zak Cole shared on X that he had fallen victim to a malicious AI-based code assistant that drained funds from his hot wallet. The culprit? A Cursor AI extension disguised as a legitimate Solidity development tool.


The Trap That Looked Legit

The extension, named “contractshark.solidity-lang”, appeared professional, complete with a sleek icon, detailed description, and over 54,000 downloads. But beneath the surface, it was a carefully engineered trap.

Once installed, the extension silently read Cole’s .env file, extracted his private key, and transmitted it to an attacker’s server. The attacker then had three days of unrestricted access to Cole’s hot wallet before finally draining it on Sunday.

“In 10+ years, I have never lost a single wei to hackers,” Cole admitted. “Then I rushed to ship a contract last week.” Fortunately, he only lost a few hundred dollars in Ether thanks to his security practice of keeping hot wallets small and isolated for project testing, with primary holdings stored securely on hardware wallets.


A Rising Threat for Crypto Developers

Security experts warn this is not an isolated incident. Hakan Unal, senior security operations lead at Cyvers, described malicious extensions as a “major attack vector” for crypto builders.

These attacks often use:

  • Fake publishers
  • Typosquatting (slightly misspelled package names)
  • Hidden key-stealing code

Unal advises developers to vet every extension, avoid storing sensitive keys in plain text, use hardware wallets, and work in isolated environments.


Wallet Drainers: Now Available for Rent

The threat is growing not just in complexity but accessibility. According to an AMLBot report published in April, wallet drainer malware is now offered as software-as-a-service, with criminals renting them for as little as $100 in USDT.

These tools have already caused significant damage:

  • In September 2024, a fake WalletConnect app on Google Play ran for over five months, stealing more than $70,000 in crypto.
  • Many fake app reviews mentioned irrelevant features—likely meant to fool unsuspecting users.

With scams becoming polished, professional, and cheap to deploy, experts say the risk to developers and investors alike has never been higher.

author avatar
Alex
Formally freelance blogger Alex is passionate writer with interest in Finance and Business, fascinated about crypto following news and covering stories.
Advertisement

You May Also Like

Business

US community banks are urging Congress to amend the GENIUS Act to stop stablecoin issuers and their partners from offering yield, warning that the...

Business

Bank of America Bitcoin ETFs are officially moving into the financial mainstream. The banking giant has authorized its wealth advisers to proactively recommend spot...

Business

The filing of Morgan Stanley Bitcoin and Solana ETFs signifies Wall Street’s increasing acceptance of regulated crypto products. The action could offer exposure to...

Finance

US Rep. Ritchie Torres is preparing a bill to crack down on insider trading in prediction markets after a controversial Polymarket wager tied to...

polkadot
Polkadot (DOT) $ 2.09 1.05%
bitcoin
Bitcoin (BTC) $ 90,874.00 0.40%
ethereum
Ethereum (ETH) $ 3,120.27 0.96%
cardano
Cardano (ADA) $ 0.392529 0.76%
xrp
XRP (XRP) $ 2.10 0.31%
stellar
Stellar (XLM) $ 0.226929 0.01%
litecoin
Litecoin (LTC) $ 80.91 0.76%