• bitcoinBitcoin (BTC) $ 66,478.00
  • ethereumEthereum (ETH) $ 1,991.27
  • tetherTether (USDT) $ 0.999198
  • bnbBNB (BNB) $ 609.90
  • xrpXRP (XRP) $ 1.33
  • usd-coinUSDC (USDC) $ 0.999743
  • solanaSolana (SOL) $ 81.84
  • tronTRON (TRX) $ 0.319169
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.090365
  • usdsUSDS (USDS) $ 0.999697
  • whitebitWhiteBIT Coin (WBT) $ 51.35
  • hyperliquidHyperliquid (HYPE) $ 38.81
  • bitcoin-cashBitcoin Cash (BCH) $ 458.90
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.241541
  • leo-tokenLEO Token (LEO) $ 9.66
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 327.38
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 8.43
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.998980
  • canton-networkCanton (CC) $ 0.152472
  • stellarStellar (XLM) $ 0.165704
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999382
  • daiDai (DAI) $ 0.999195
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 53.58
  • rainRain (RAIN) $ 0.008433
  • memecoreMemeCore (M) $ 2.22
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999589
  • hedera-hashgraphHedera (HBAR) $ 0.088838
  • avalanche-2Avalanche (AVAX) $ 8.67
  • wethWETH (WETH) $ 2,268.37
  • zcashZcash (ZEC) $ 213.45
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.845931
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 316.04
  • the-open-networkToncoin (TON) $ 1.23
  • crypto-com-chainCronos (CRO) $ 0.070523
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.097241
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,493.25
  • pax-goldPAX Gold (PAXG) $ 4,504.09
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.676133
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • uniswapUniswap (UNI) $ 3.36
  • polkadotPolkadot (DOT) $ 1.26
  • global-dollarGlobal Dollar (USDG) $ 0.999731
  • okbOKB (OKB) $ 84.22
  • pi-networkPi Network (PI) $ 0.176909
  • falcon-financeFalcon USD (USDF) $ 0.997216
  • skySky (SKY) $ 0.070863
  • aster-2Aster (ASTER) $ 0.658959
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.16
  • aaveAave (AAVE) $ 95.43
  • ripple-usdRipple USD (RLUSD) $ 0.999827
  • pepePepe (PEPE) $ 0.000003
  • bitget-tokenBitget Token (BGB) $ 1.94
  • bfusdBFUSD (BFUSD) $ 0.999201
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • ondo-financeOndo (ONDO) $ 0.263916
  • ethereum-classicEthereum Classic (ETC) $ 7.97
  • siren-2Siren (SIREN) $ 1.71
  • internet-computerInternet Computer (ICP) $ 2.22
  • gatechain-tokenGate (GT) $ 6.52
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kucoin-sharesKuCoin (KCS) $ 7.96
  • pump-funPump.fun (PUMP) $ 0.001713
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 69.17
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.092146
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • kaspaKaspa (KAS) $ 0.032330
  • usdtbUSDtb (USDTB) $ 0.999118
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • nexoNEXO (NEXO) $ 0.875681
  • render-tokenRender (RENDER) $ 1.66
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • worldcoin-wldWorldcoin (WLD) $ 0.272345
  • midnight-3Midnight (NIGHT) $ 0.049897
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.64
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • morphoMorpho (MORPHO) $ 1.49
  • usddUSDD (USDD) $ 0.997378
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.090191
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.03
  • wbnbWrapped BNB (WBNB) $ 759.61
  • aptosAptos (APT) $ 0.920025
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.080858
  • official-trumpOfficial Trump (TRUMP) $ 2.86
  • flare-networksFlare (FLR) $ 0.007695
  • hash-2Provenance Blockchain (HASH) $ 0.011210
  • ousgOUSG (OUSG) $ 114.73
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • filecoinFilecoin (FIL) $ 0.802633
  • beldexBeldex (BDX) $ 0.079866
  • xdce-crowd-saleXDC Network (XDC) $ 0.030358
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • yldsYLDS (YLDS) $ 0.999928
  • ghoGHO (GHO) $ 0.999033
  • vechainVeChain (VET) $ 0.006577
  • usual-usdUsual USD (USD0) $ 0.998448
  • arbitrumArbitrum (ARB) $ 0.088669
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.234986
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • justJUST (JST) $ 0.059488
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • stable-2​​Stable (STABLE) $ 0.024595
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.142772
  • layerzeroLayerZero (ZRO) $ 1.99
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • true-usdTrueUSD (TUSD) $ 0.997758
  • a7a5A7A5 (A7A5) $ 0.012227
  • fasttokenFasttoken (FTN) $ 1.09
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.36
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.651874
  • euro-coinEURC (EURC) $ 1.15
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • chilizChiliz (CHZ) $ 0.039459
  • dashDash (DASH) $ 31.65
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • blockstackStacks (STX) $ 0.216662
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998798
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006246
  • tezosTezos (XTZ) $ 0.342563
  • kinesis-goldKinesis Gold (KAU) $ 151.97
  • hastra-primePRIME (PRIME) $ 1.03
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • ether-fiEther.fi (ETHFI) $ 0.455978
  • sei-networkSei (SEI) $ 0.053284
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • decredDecred (DCR) $ 20.50
  • usxUSX (USX) $ 0.999415
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • dexeDeXe (DEXE) $ 7.40
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • sun-tokenSun Token (SUN) $ 0.017334
  • cocaCOCA (COCA) $ 1.30
  • apenftAINFT (NFT) $ 0.00000033
  • adi-tokenADI (ADI) $ 4.03
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • gnosisGnosis (GNO) $ 117.95
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • usdaiUSDai (USDAI) $ 0.999565
  • curve-dao-tokenCurve DAO (CRV) $ 0.207420
  • aerodrome-financeAerodrome Finance (AERO) $ 0.319851
  • conflux-tokenConflux (CFX) $ 0.055082
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • riverRiver (RIVER) $ 14.47
  • kite-2Kite (KITE) $ 0.155694
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 2.80
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • bitcoin-svBitcoin SV (BSV) $ 13.56
  • fraxLegacy Frax Dollar (FRAX) $ 0.982465
  • venice-tokenVenice Token (VVV) $ 5.98
  • kaiaKaia (KAIA) $ 0.045733
  • flokiFLOKI (FLOKI) $ 0.000027
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • crvusdcrvUSD (CRVUSD) $ 0.998249
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • jasmycoinJasmyCoin (JASMY) $ 0.005310
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • official-foOfficial FO (FO) $ 0.263170
  • noonNoon (NOON) $ 0.751949
  • celestiaCelestia (TIA) $ 0.291328
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kinesis-silverKinesis Silver (KAG) $ 69.10
  • lido-daoLido DAO (LDO) $ 0.303939
  • the-graphThe Graph (GRT) $ 0.023471
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • spx6900SPX6900 (SPX) $ 0.266558
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • monadMonad (MON) $ 0.022435
  • olympusOlympus (OHM) $ 15.39
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • btse-tokenBTSE Token (BTSE) $ 1.47
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • syrupMaple Finance (SYRUP) $ 0.202837

NOFX AI Bug Exposes API Keys, SlowMist Warns of Major Risk

0 0


NOFX AI, an open-source automated trading system built on DeepSeek/Qwen AI. It is facing a serious security crisis after SlowMist uncovered vulnerabilities. That could expose exchange API keys and private keys. The issue affects users across major exchanges, including Binance, Hyperliquid and Aster DEX. SlowMist now urges deployers to take immediate action before attackers exploit these weaknesses to drain funds.

吴说获悉,慢雾安全团队发布报告称,开源加密货币期货自动交易系统 NOFX AI(基于 DeepSeek/Qwen AI)存在严重安全漏洞,可能导致交易所 API Key 和私钥泄露。该漏洞源于项目在多个版本中默认开启 “管理员模式” 且未进行鉴权检查,攻击者可直接访问 /api/exchanges 获取 Binance、Hyperliquid、Aster…

— 吴说区块链 (@wublockchain12) November 17, 2025

Admin Mode Flaw Leaves Keys Fully Exposed

SlowMist began investigating the system after receiving a warning from a community security researcher. The team quickly discovered that several versions of NOFX AI shipped with admin mode. It is enabled by default and worse, the system performed no authentication checks at all. Because of this, anyone could simply visit the public /api/exchanges endpoint and instantly retrieve sensitive data. Such as API keys, secret keys and private wallet keys.

This issue stemmed from a commit published on October 31. Which hardcoded admin mode to “true” in the config file and database migration scripts. The server then skipped all authorization whenever admin mode was active. In simple terms, any NOFX AI instance running with default settings was effectively unlocked. That is to say, anyone with the link could walk in and take the keys, literally.

Patch Attempts Didn’t Fix the Core Problem

Developers tried to address the issue on November 5 by adding JWT token verification. However, SlowMist found that the patch barely changed the situation. The default configuration still shipped with a publicly known JWT secret. It allows attackers to generate valid tokens and continue accessing sensitive endpoints. Even worse, in addition, the core /api/exchanges endpoint continued returning sensitive fields in plain JSON; nothing was masked or encrypted.

SlowMist also confirmed that the most recent dev branch still contained:

  • Admin mode set to “true” by default
  • Default JWT keys left untouched
  • Sensitive data returned without restriction

Because the main branch still uses the older, zero-auth version, thousands of deployments remain wide open on the public internet.

Binance and OKX Step In to Protect Users

Once SlowMist realized the scale of the exposure. They contacted Binance and OKX to coordinate emergency protection measures. Together, the teams reviewed affected API keys and forced resets for users at risk. All impacted CEX users have now been notified, and their keys have been revoked. However, the teams could not reach all Aster and Hyperliquid users due to decentralized wallet structures. SlowMist now urges anyone using NOFX AI on these platforms to review their setup immediately.

Users Told to Disable Admin Mode and Replace Keys Now

SlowMist recommends all deployers:

  • Disable admin mode immediately
  • Replace all API keys and private keys
  • Change the JWT secret to a strong, random value
  • Restrict sensitive endpoints
  • Avoid exposing NOFX AI directly to the public internet

Open-source AI trading tools are growing fast. But this case highlights the risks of deploying early-stage systems without full security audits. Until NOFX AI fully fixes these flaws, users should treat any public deployment as high-risk.



Source link

Leave A Reply

Your email address will not be published.