Skip to content
NOFX AI Vulnerability Exposes API Keys and Private Wallets

NOFX AI Vulnerability Exposes API Keys and Private Wallets

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

SlowMist identified a critical vulnerability in the NOFX AI trading system, which shipped with an 'admin mode' enabled by default and lacked proper authentication. This flaw allows unauthorized access to sensitive API keys and private wallet information, affecting users on platforms like Binance, Hyperliquid, and Aster DEX. Despite a developer patch attempt, the core issue remains unresolved due to a publicly known default JWT secret.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track Aster in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed