A fake GitHub trading bot posing as a Solana tool has drained users' wallets by stealing private keys.
The bot used hidden malicious code to steal private keys and send them to a hacker server, bypassing security checks.
SlowMist warns users to avoid blindly trusting open-source tools with wallet access.
The incident serves as a reminder for users to be cautious when using GitHub projects that deal with private keys, suggesting testing in isolated environments.