Security-oriented researchers and companies have warned about a popular, open-source Polymarket copy trading bot hosted on GitHub.  The bot was created by a developerSecurity-oriented researchers and companies have warned about a popular, open-source Polymarket copy trading bot hosted on GitHub.  The bot was created by a developer

Security researchers issue alert over malicious code found in a Polymarket copy-trading bot on GitHub

2025/12/21 23:55
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Security-oriented researchers and companies have warned about a popular, open-source Polymarket copy trading bot hosted on GitHub. 

The bot was created by a developer under the handle “Trust412,” and reportedly contains hidden malicious code across multiple commits and dependencies. 

Polymarket copy traders warned of malicious private key-stealing codeSource: @hunterweb303 via X/Twitter

SlowMist sounds Polymarket trading bot warning 

Earlier today, December 21, 23pds, SlowMist’s Chief Information Security Officer, retweeted a warning from a community user about a malicious code in a Polymarket copy-trading bot on GitHub, posing security risks. 

The incident has reminded many that the crypto bot market still has many vulnerabilities, which is why scrutinizing GitHub repositories for hidden threats is now non-negotiable. 

According to the post 23pds interacted with, this code was deliberately put there, but its malicious nature was disguised while the author revised it repeatedly to ensure that it evaded detection. 

This occurred across multiple submissions in the “polymarket-copy-trading-bot” repository, potentially exposing users to fund theft.

The hidden code in the bot’s program made it scan and read configuration files automatically, extract private keys, and transfer them to a remote server controlled by the hackers.  

Users are urged to be cautious with any unaudited code repositories. In 23pds’s post, he alleged this is not the first time the method is being used to target GitHub and its users and that it will not be the last of such incidents. 

How to avoid the private key exploits 

The most crucial thing about this form of exploit is that it depends on the individual to kick-start the process, which means extra caution would do a lot to prevent repeated cases. 

The exploit is a classic supply-chain attack on open-source tools. It requires users to first install the bot, which many do in an effort to copy successful traders on Polymarket. These users input their private keys for signing trades, thereby unknowingly exposing them.

Anyone who finds themselves in such a predicament is advised to immediately delete the repository if it has been downloaded, assume any wallet linked to it has been compromised, and move all funds to a new one as quickly as it can be done. 

It also does not help matters that similar issues have come up in other Polymarket bot repos. So it has become crucial to scrutinize third-party trading scripts to be on the safe side. 

It should be noted that the Polymarket platform has not been hacked; the bots that have been wreaking this havoc are unofficial ones, which pose high risks since they require direct access to users’ private keys.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

시장 기회
OpenLedger 로고
OpenLedger 가격(OPEN)
$0.20035
$0.20035$0.20035
-3.74%
USD
OpenLedger (OPEN) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

추천 콘텐츠

Crypto Shorts Suffer $300M Flush As Bitcoin Hits $80,000

Crypto Shorts Suffer $300M Flush As Bitcoin Hits $80,000

Bearish cryptocurrency bets have seen a liquidation squeeze during the past day as Bitcoin and other assets have gone through a price surge. Bitcoin Crosses $80
공유하기
NewsBTC2026/05/05 11:00
Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
공유하기
BitcoinEthereumNews2025/09/18 00:36
Melania Trump humiliated her husband as he tries to outrun his decay: analysts

Melania Trump humiliated her husband as he tries to outrun his decay: analysts

First lady Melania Trump just handed President Donald Trump his biggest humiliation yet as the president tried to outrun his decay, according to two political analysts
공유하기
Rawstory2026/05/05 11:42

Starter Gold Rush: Win $2,500!

Starter Gold Rush: Win $2,500!Starter Gold Rush: Win $2,500!

Start your first trade & capture every Alpha move