Scan to Download Gate App
qrCode
More Download Options
Don't remind me again today

Slow Fog discloses serious vulnerabilities in NOFX AI: which may lead to the leakage of exchange API Key and Private Key.

robot
Abstract generation in progress

Wu reported that the Slow Fog security team released a report stating that the open source Crypto Assets futures automated trading system NOFX AI (based on DeepSeek/Qwen AI) has serious security vulnerabilities that may lead to the leakage of exchange API Key and Private Key. The vulnerability originates from the project having “admin mode” enabled by default in multiple versions without authentication checks, allowing attackers to directly access /api/exchanges to obtain key information from exchanges such as Binance, Hyperliquid, and Aster DEX. Although the update on November 5 introduced a JWT verification mechanism, the default keys can still be exploited, and the essence of the vulnerability has not been fixed. Slow Fog recommends that deployers immediately disable admin mode, change JWT keys, and minimize interface return information to prevent asset risks.

HYPE3.39%
ASTER2.9%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)