Coinfomania
NOFX AI Vulnerability Exposes User API and Private Keys
First seen 17 Nov 2025, 19:15 UTC
•
•79% similarity
•54.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
SlowMist identified a critical vulnerability in the NOFX AI automated trading system, which shipped with an 'admin mode' enabled by default, allowing unauthorized access to sensitive API and private wallet keys. Users of exchanges including Binance, Hyperliquid, and Aster DEX are at risk of fund theft due to this flaw. Despite attempts to patch the issue, the core problem remains unresolved as the default JWT secret was publicly accessible.
ThreatCluster AI