SlowMist Warns AI Coding Tools May Expose Crypto to Silent Attacks
SlowMist has uncovered a critical vulnerability in AI-powered coding tools that threatens cryptocurrency developers. The flaw allows malicious code execution simply by opening untrusted project folders, with popular platforms like Cursor demonstrating particular susceptibility during controlled tests.
Attackers are embedding poisoned prompts in common project files (README.md, LICENSE.txt) that AI assistants automatically interpret as executable instructions. This creates a silent attack vector - North Korean threat actors have already weaponized similar techniques through smart contracts, leaving no blockchain traces while compromising systems.
The report highlights growing risks as AI tools permeate crypto development workflows. Projects using vulnerable IDEs could see digital assets stolen, credentials compromised, or malware deployed through routine operations like folder navigation.