Malicious GitHub Repo Disguised as Crypto Exploit Exposed via LLM-Assisted Review

RSync25 · x · 2026-08-05

A GitHub repository claiming to reproduce a Coldcard crypto wallet RNG vulnerability gained significant traction recently. However, an LLM-assisted code review revealed that the project contains a malicious dependency that downloads and executes an infostealer targeting wallet seeds, private keys, and passwords.

This incident highlights both a targeted supply chain attack against crypto users and the growing potential of using LLMs to augment code security audits.

Original post →

More from coding & agent

coding & agent channel →