🎉 亲爱的广场小伙伴们,福利不停,精彩不断!目前广场上这些热门发帖赢奖活动火热进行中,发帖越多,奖励越多,快来 GET 你的专属好礼吧!🚀
🆘 #Gate 2025年中社区盛典# |广场十强内容达人评选
决战时刻到!距离【2025年中社区盛典】广场达人评选只剩 1 天,你喜爱的达人,就差你这一票冲进 C 位!在广场发帖、点赞、评论就能攒助力值,帮 Ta 上榜的同时,你自己还能抽大奖!iPhone 16 Pro Max、金牛雕塑、潮流套装、合约体验券 等你抱走!
详情 👉 https://www.gate.com/activities/community-vote
1️⃣ #晒出我的Alpha积分# |晒出 Alpha 积分&收益
Alpha 积分党集合!带话题晒出你的 Alpha 积分图、空投中奖图,即可瓜分 $200 Alpha 代币盲盒,积分最高直接抱走 $100!分享攒分秘籍 / 兑换经验,中奖率直线上升!
详情 👉 https://www.gate.com/post/status/12763074
2️⃣ #ETH百万矿王争霸赛# |ETH 链上挖矿晒收益
矿工集结!带话题晒出你的 Gate ETH 链上挖矿收益图,瓜分 $400 晒图奖池,收益榜第一独享 $200!谁才是真 ETH 矿王?开晒见分晓!
详情 👉 https://www.gate.com/pos
Rogue AI Code Assistant Targets Ethereum Developer, Steals Crypto Funds - Crypto Economy
TL;DR
Ethereum core developer Zak Cole recently experienced a sophisticated crypto wallet-draining attack involving a rogue AI code assistant. Cole installed the “contractshark.solidity-lang” extension, which appeared legitimate with professional design and over 54,000 downloads, but secretly transmitted his private key to an attacker’s server. Over three days, the attacker gained access to his hot wallet before draining the funds.

Cole reported the loss on X, noting it amounted to only a few hundred dollars in Ether due to his careful use of small, project-specific wallets. The incident also highlights how even experienced developers can be deceived by increasingly polished and realistic-looking tools.
Extensions Become Major Attack Vector For Crypto Builders
Malicious VS Code and browser extensions are increasingly recognized as major attack vectors, according to Hakan Unal, senior security operations lead at blockchain security firm Cyvers. Threat actors use tactics like fake publishers, typosquatting, and professional-looking copy to trick developers into granting access to private keys. Wallet drainers are now even sold on a software-as-a-service basis, sometimes renting for as little as $100 USDt, making attacks accessible to a wider range of scammers. These developments suggest that the barrier for entry into crypto-targeted cybercrime is lower than ever, allowing even less technical attackers to compromise wallets successfully.
Historical Incidents Highlight Persistent Risks
This incident follows similar attacks, including a September 2024 WalletConnect Protocol scam that stole over $70,000 from investors while masquerading as a legitimate app on Google Play for more than five months. Fake reviews were used to mimic genuine feedback, illustrating the lengths attackers go to exploit trust. Experts recommend vetting all third-party extensions, avoiding storing secrets in plain text, using hardware wallets, and developing in isolated environments to reduce exposure.

Cole’s experience demonstrates that even highly experienced blockchain developers are not immune to emerging threats. Nevertheless, by adhering to strong security practices, crypto professionals can limit their risk, protect major holdings, and continue innovating confidently in the blockchain space. As attackers adopt AI-driven tactics and scalable SaaS models, vigilance and proper safeguards remain essential for anyone interacting with digital assets, whether for development, investment, or experimental testing purposes.