NOFX AI Vulnerability Exposes User API and Private Keys

NOFX AI Vulnerability Exposes User API and Private Keys

First seen 17 Nov 2025, 19:15 UTC BitgetCoinfomania 79% similarity 54.6

Article Content

Browse articles
ThreatCluster

SlowMist identified a critical vulnerability in the NOFX AI automated trading system, which shipped with an 'admin mode' enabled by default, allowing unauthorized access to sensitive API and private wallet keys. Users of exchanges including Binance, Hyperliquid, and Aster DEX are at risk of fund theft due to this flaw. Despite attempts to patch the issue, the core problem remains unresolved as the default JWT secret was publicly accessible.

ThreatCluster AI

Community

Browse all →