Coinfomania
NOFX AI Vulnerability Exposes API Keys and Private Wallets
First seen 2 Dec 2025, 18:33 UTC
•
•79% similarity
•42.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
SlowMist identified a critical vulnerability in the NOFX AI trading system, which shipped with an 'admin mode' enabled by default and lacked proper authentication. This flaw allows unauthorized access to sensitive API keys and private wallet information, affecting users on platforms like Binance, Hyperliquid, and Aster DEX. Despite a developer patch attempt, the core issue remains unresolved due to a publicly known default JWT secret.
ThreatCluster AI