Security Alert: Malicious Code Found in Polymarket Copy-Trading Bot on GitHub
Security researchers have uncovered a critical vulnerability in an open-source Polymarket copy-trading bot hosted on GitHub. The bot, developed by 'Trust412,' contained hidden malicious code across multiple commits and dependencies, according to warnings from SlowMist and community investigators.
The code was designed to evade detection through repeated revisions, scanning configuration files to extract private keys and transmit them to a remote server. This deliberate obfuscation highlights persistent risks in unaudited crypto trading tools, particularly those leveraging GitHub repositories.
The incident underscores the need for heightened scrutiny of third-party trading bots, as even seemingly legitimate projects can harbor exploits targeting digital asset wallets. SlowMist's public alert reinforces broader industry concerns about supply-chain attacks in decentralized finance infrastructure.