SlowMist uncovers major security flaws in NOFX AI that exposed user keys

Source Cryptopolitan

SlowMist, a blockchain security firm, has led an investigation that has uncovered critical vulnerabilities in NOFX AI, an open-source cryptocurrency futures trading system built on DeepSeek and Qwen’s large-language-model architecture. 

According to findings published on Web3Caff, flaws in multiple versions of the system left some users exposed to credential leakage, with attackers able, in certain cases, to obtain wallet private keys and centralized and decentralized exchange API credentials.

After making those discoveries, the SlowMist team reached out to the security teams of Binance and OKX, who worked with the team to identify affected users and revoke compromised keys.

Authentication flaws exposed in multiple versions

The SlowMist investigation began after the team received intelligence from a community researcher operating under the handle @Endlessss20, who suspected that NOFX AI might be leaking exchange API keys. 

Cos, the founder of SlowMist, who uses the X handle @evilcos, initially had praise for NOFX AI’s open-source efforts, calling them commendable.

However, he then stated that the risks they have “disclosed have already led to real theft incidents, where some users’ wallet private keys and CEX/DEX API Keys were leaked as a result.”

Cos added that SlowMist’s initial disclosure effort was deliberately coordinated with exchange security teams to ensure that those affected were notified before details were released publicly.

SlowMist’s subsequent analysis identified two core authentication issues affecting different commit generations of the open-source repository.

This issue was reportedly present in older and newer versions of the open-source platform; the system reportedly ran in an “Authorization Required” state that nonetheless lacked actual access controls, leaving sensitive administrator (admin) functions open without authentication.

So, attackers could interact with admin APIs without needing credentials.

Compounding these authentication weaknesses, one of the system’s API endpoints returned sensitive connection data by default, including API keys and associated secrets for exchanges such as Binance, Hyperliquid, and Aster DEX.

Coordinated security response with exchanges

After confirming the severity of the issues, SlowMist contacted the security divisions of Binance and OKX.

They reportedly set up a joint security operations room where SlowMist supplied intelligence and an impact assessment, while the exchange teams independently analyzed and verified the compromised API data.

The groups then worked backwards from exposed keys to identify at-risk accounts on their platforms.

The exchanges initiated countermeasures, informing each affected user and immediately revoking their API keys, secret keys, and any linked automation credentials.  “As of November 17, all affected CEX users have been notified, and their relevant keys have been revoked, and their assets are safe,” SlowMist stated in its report.

However, it admitted that reaching users on decentralized exchanges was relatively more difficult. SlowMist said they and the Binance team tried to contact a small number of Aster and Hyperliquid users directly, but could not “due to the decentralized wallet addresses.”

“If you are using automated trading systems on Aster or Hyperliquid, please promptly check and address any related risks,” the security firm warned users.

Warnings for the AI-trading ecosystem

SlowMist also pointed out that there is a rise in large-scale AI model quantization projects; however, most open-source implementations are still in their early stages.

Therefore, those deploying such emerging open-source systems are advised to “conduct thorough code security audits and strengthen risk control measures to avoid financial losses.”

The security firm also had recommendations for the NOFX AI team and users, advising them to refuse to run the program if a template key is detected, disable admin mode unless explicitly configured and protected with a strong password and OTP authentication, and redesign sensitive endpoints to return only non-critical metadata while requiring secondary verification for private-key or API-key access, among others.

The firm warned that “until the development team completes these fixes, any deployment to the public internet should be considered high-risk.”

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Bitcoin's 2025 Gains Erased: Who Ended the BTC Bull Market?After slumping below $93,500, 2025 Bitcoin price gains have been completely wiped out. Investors are puzzled as to why its bull market, underpinned by political tailwinds, institutionaliz
Author  TradingKey
7 hours ago
After slumping below $93,500, 2025 Bitcoin price gains have been completely wiped out. Investors are puzzled as to why its bull market, underpinned by political tailwinds, institutionaliz
placeholder
Oil Extends Losses as Russian Port Resumes Operations, Easing Supply FearsOil prices fell further on Monday as market participants reacted to signs of resumed activity at Russia’s key Novorossiysk export terminal on the Black Sea, easing concerns over a prolonged supply disruption after a Ukrainian drone strike last week.
Author  Mitrade
10 hours ago
Oil prices fell further on Monday as market participants reacted to signs of resumed activity at Russia’s key Novorossiysk export terminal on the Black Sea, easing concerns over a prolonged supply disruption after a Ukrainian drone strike last week.
placeholder
Bitcoin slides deeper into red as bears lean on $96,600 wall and eye $90,000Bitcoin extends its decline after failing to reclaim $96,500, trading below $95,000, the 100-hour SMA and a bearish trend line near $96,600; unless bulls can force a decisive close back above $96,600–$97,200, the short-term path of least resistance stays lower, with $92,500, $90,000 and the main $88,500 support zone in focus.
Author  Mitrade
14 hours ago
Bitcoin extends its decline after failing to reclaim $96,500, trading below $95,000, the 100-hour SMA and a bearish trend line near $96,600; unless bulls can force a decisive close back above $96,600–$97,200, the short-term path of least resistance stays lower, with $92,500, $90,000 and the main $88,500 support zone in focus.
placeholder
Bitcoin briefly loses 2025 gains as crypto plunges over the weekend.Bitcoin experienced a sharp decline this weekend, briefly erasing its 2025 gains and dipping below its year-opening value of $93,507. The cryptocurrency fell to a low of $93,029 on Sunday, representing a 25% drop from its all-time high in October. Although it has rebounded slightly to around $94,209, the pressures on the market remain significant. The downturn occurred despite the reopening of the U.S. government on Thursday, which many had hoped would provide essential support for crypto markets. This year initially appeared promising for cryptocurrencies, particularly after the inauguration of President Donald Trump, who has established the most pro-crypto administration thus far. However, ongoing political tensions—including Trump's tariff strategies and the recent government shutdown, lasting a historic 43 days—have contributed to several rapid price pullbacks for Bitcoin throughout the year. Market dynamics are also being influenced by Bitcoin whales—investors holding large amounts of Bitcoin—who have been offloading portions of their assets, consequently stalling price rallies even as positive regulatory developments emerge. Despite these sell-offs, analysts from Glassnode argue that this behavior aligns with typical patterns seen among long-term investors during the concluding stages of bull markets, suggesting it is not indicative of a mass exodus. Notably, Bitcoin is not alone in its struggles, as Ethereum and Solana have also recorded declines of 7.95% and 28.3%, respectively, since the start of the year, while numerous altcoins have faced even steeper losses. Looking ahead, questions linger regarding the viability of the four-year cycle thesis, particularly given the increasing institutional support and regulatory frameworks now in place in the crypto landscape. Matt Hougan, chief investment officer at Bitwise, remains optimistic, suggesting a potential Bitcoin resurgence in 2026 driven by the “debasement trade” thesis and a broader trend toward increased adoption of stablecoins, tokenization, and decentralized finance. Hougan emphasized the soundness of the underlying fundamentals, pointing to a positive outlook for the sector in the longer term.
Author  Mitrade
14 hours ago
Bitcoin experienced a sharp decline this weekend, briefly erasing its 2025 gains and dipping below its year-opening value of $93,507. The cryptocurrency fell to a low of $93,029 on Sunday, representing a 25% drop from its all-time high in October. Although it has rebounded slightly to around $94,209, the pressures on the market remain significant. The downturn occurred despite the reopening of the U.S. government on Thursday, which many had hoped would provide essential support for crypto markets. This year initially appeared promising for cryptocurrencies, particularly after the inauguration of President Donald Trump, who has established the most pro-crypto administration thus far. However, ongoing political tensions—including Trump's tariff strategies and the recent government shutdown, lasting a historic 43 days—have contributed to several rapid price pullbacks for Bitcoin throughout the year. Market dynamics are also being influenced by Bitcoin whales—investors holding large amounts of Bitcoin—who have been offloading portions of their assets, consequently stalling price rallies even as positive regulatory developments emerge. Despite these sell-offs, analysts from Glassnode argue that this behavior aligns with typical patterns seen among long-term investors during the concluding stages of bull markets, suggesting it is not indicative of a mass exodus. Notably, Bitcoin is not alone in its struggles, as Ethereum and Solana have also recorded declines of 7.95% and 28.3%, respectively, since the start of the year, while numerous altcoins have faced even steeper losses. Looking ahead, questions linger regarding the viability of the four-year cycle thesis, particularly given the increasing institutional support and regulatory frameworks now in place in the crypto landscape. Matt Hougan, chief investment officer at Bitwise, remains optimistic, suggesting a potential Bitcoin resurgence in 2026 driven by the “debasement trade” thesis and a broader trend toward increased adoption of stablecoins, tokenization, and decentralized finance. Hougan emphasized the soundness of the underlying fundamentals, pointing to a positive outlook for the sector in the longer term.
placeholder
Gold Price Forecast: XAU/USD recovers above $4,100, hawkish Fed might cap gainsGold price (XAU/USD) recovers some lost ground to near $4,105, snapping the two-day losing streak during the early European session on Friday. The precious metal edges higher on the softer US Dollar (USD).  Traders will take more cues from the Fedspeak later on Monday.
Author  FXStreet
16 hours ago
Gold price (XAU/USD) recovers some lost ground to near $4,105, snapping the two-day losing streak during the early European session on Friday. The precious metal edges higher on the softer US Dollar (USD).  Traders will take more cues from the Fedspeak later on Monday.
goTop
quote