NOFX AI Vulnerability Exposes API Keys and Private Wallets

NOFX AI Vulnerability Exposes API Keys and Private Wallets

First seen 2 Dec 2025, 18:33 UTC BitgetCoinfomania 79% similarity 42.4

Article Content

Browse articles
ThreatCluster

SlowMist identified a critical vulnerability in the NOFX AI trading system, which shipped with an 'admin mode' enabled by default and lacked proper authentication. This flaw allows unauthorized access to sensitive API keys and private wallet information, affecting users on platforms like Binance, Hyperliquid, and Aster DEX. Despite a developer patch attempt, the core issue remains unresolved due to a publicly known default JWT secret.

ThreatCluster AI

Community

Browse all →