<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>WalletConnect Protocol Archives - Coin Engineer</title>
	<atom:link href="https://coinengineer.net/blog/tag/walletconnect-protocol/feed/" rel="self" type="application/rss+xml" />
	<link>https://coinengineer.net/blog/tag/walletconnect-protocol/</link>
	<description>Btc, Coins, Pre-Sale, DeFi, NFT</description>
	<lastBuildDate>Wed, 13 Aug 2025 15:16:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://coinengineer.net/blog/wp-content/uploads/2024/04/cropped-Coin-Engineer-Logo-Favicon-2-32x32.png</url>
	<title>WalletConnect Protocol Archives - Coin Engineer</title>
	<link>https://coinengineer.net/blog/tag/walletconnect-protocol/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Ethereum Developer&#8217;s Wallet Drained! What Happened?</title>
		<link>https://coinengineer.net/blog/ethereum-developers-wallet-drained-what-happened/</link>
					<comments>https://coinengineer.net/blog/ethereum-developers-wallet-drained-what-happened/#respond</comments>
		
		<dc:creator><![CDATA[Emre Yumlu]]></dc:creator>
		<pubDate>Wed, 13 Aug 2025 15:30:11 +0000</pubDate>
				<category><![CDATA[Crypto News]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[core dev]]></category>
		<category><![CDATA[cursor ai]]></category>
		<category><![CDATA[drain]]></category>
		<category><![CDATA[ether]]></category>
		<category><![CDATA[ethereum]]></category>
		<category><![CDATA[malicious extension]]></category>
		<category><![CDATA[wallet]]></category>
		<category><![CDATA[WalletConnect Protocol]]></category>
		<category><![CDATA[Zak Cole]]></category>
		<guid isPermaLink="false">https://coinengineer.net/blog/?p=47936</guid>

					<description><![CDATA[<p>Ethereum core developer Zak Cole lost access to his funds after a fake artificial intelligence extension stole his private key. This incident once again highlights how sophisticated wallet drainer attacks in the crypto space have become. Threat From a Malicious Extension Cole explained that he had installed a Cursor AI extension named “contractshark.solidity-lang,” which appeared</p>
<p>The post <a href="https://coinengineer.net/blog/ethereum-developers-wallet-drained-what-happened/">Ethereum Developer&#8217;s Wallet Drained! What Happened?</a> appeared first on <a href="https://coinengineer.net/blog">Coin Engineer</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="69" data-end="316"><a href="https://coinengineer.net/blog/standard-chartered-makes-major-revision-to-ethereum-price-forecast/"><strong>Ethereum</strong> </a>core developer <strong data-start="93" data-end="105">Zak Cole</strong> lost access to his funds after a fake artificial intelligence extension stole his private key. This incident once again highlights how sophisticated <strong data-start="255" data-end="273">wallet drainer</strong> attacks in the crypto space have become.</p>
<h3 data-start="318" data-end="357">Threat From a Malicious Extension</h3>
<p data-start="359" data-end="761">Cole explained that he had installed a <strong>Cursor AI</strong> extension named “contractshark.solidity-lang,” which appeared trustworthy with a professional icon, detailed description, and over 54,000 downloads. However, the extension read his <strong data-start="589" data-end="597">.env</strong> file and transmitted the private key to the attacker’s server. This gave the attacker three days of access to his hot wallet before draining the funds on Sunday.</p>
<p data-start="763" data-end="1097">“In over 10 years, I have never lost a single wei to hackers. Then I rushed to deliver a contract last week, and this happened,” Cole said. He noted that the loss was limited to only a few hundred dollars worth of <strong data-start="977" data-end="986">Ether</strong>, as he keeps his main holdings on hardware wallets and uses small, project-specific hot wallets for testing.</p>
<blockquote class="twitter-tweet" data-width="550" data-dnt="true">
<p lang="en" dir="ltr">I&#39;ve been in crypto for over 10 years and I’ve Never been hacked. Perfect OpSec record.</p>
<p>Yesterday, my wallet was drained by a malicious <a href="https://twitter.com/cursor_ai?ref_src=twsrc%5Etfw">@cursor_ai</a> extension for the first time.</p>
<p>If it can happen to me, it can happen to you. Here’s a full breakdown. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9f5.png" alt="🧵" class="wp-smiley"  /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f447.png" alt="👇" class="wp-smiley"  /></p>
<p>&mdash; zak.eth (@0xzak) <a href="https://twitter.com/0xzak/status/1955265807807545763?ref_src=twsrc%5Etfw">August 12, 2025</a></p></blockquote>
<p></p>
<h3 data-start="1099" data-end="1132">Wallet Drainers on the Rise</h3>
<p data-start="1134" data-end="1428"><strong data-start="1134" data-end="1153">Wallet drainers</strong>—malware designed to steal digital assets—are an increasing threat to cryptocurrency investors. In September 2024, malware disguised as the <strong data-start="1293" data-end="1319">WalletConnect Protocol</strong> remained live on the Google Play Store for over five months, stealing more than $70,000 in digital assets.</p>
<p data-start="1430" data-end="1795">Hakan Unal, senior security operations lead at blockchain security firm Cyvers, warned that fake publishers and typosquatting techniques are being used to steal developers’ private keys. He advises developers to carefully vet extensions, avoid storing sensitive data in plain text or <strong data-start="1714" data-end="1722">.env</strong> files, use <strong data-start="1734" data-end="1754">hardware wallets</strong>, and develop in isolated environments.</p>
<h3 data-start="1797" data-end="1828">Attacks Can Now Be Rented</h3>
<p data-start="1830" data-end="2025">According to an April 2025 report from crypto security firm AMLBot, these types of <strong data-start="1913" data-end="1931">wallet drainer</strong> tools are now offered under a SaaS model. Scammers can rent them for as little as 100 USDT.</p>
<p data-start="2027" data-end="2164" data-is-last-node="" data-is-only-node="">These developments show that security has become more critical than ever for both developers and investors in the <strong data-start="2141" data-end="2151">crypto</strong> ecosystem.</p>
<p data-start="2027" data-end="2164" data-is-last-node="" data-is-only-node=""><em class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">You can also freely share your thoughts and comments about the topic in the comment section. Additionally, don’t forget to follow us on our <a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" href="https://t.me/coinengineernews" target="_blank" rel="nofollow noopener" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)"><strong class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">Telegram, </strong></a><a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" href="https://www.youtube.com/@CoinEngineer" target="_blank" rel="nofollow noopener" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)"><strong class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">YouTube</strong></a>, and <a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" href="https://twitter.com/coinengineers" target="_blank" rel="nofollow noopener" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)"><strong class="darkmysite_style_txt_border darkmysite_processed" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">Twitter</strong></a> channels for the latest <a class="darkmysite_style_txt_border darkmysite_style_link darkmysite_processed" title="News" href="https://coinengineer.net/blog/news/" data-internallinksmanager029f6b8e52c="7" data-darkmysite_alpha_bg="rgba(0, 0, 0, 0)">news</a> and updates.</em></p>
<p>The post <a href="https://coinengineer.net/blog/ethereum-developers-wallet-drained-what-happened/">Ethereum Developer&#8217;s Wallet Drained! What Happened?</a> appeared first on <a href="https://coinengineer.net/blog">Coin Engineer</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coinengineer.net/blog/ethereum-developers-wallet-drained-what-happened/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url='https://coinengineer.net/blog/wp-content/uploads/2025/08/ethereum_hack_ce.jpg' type='image/webp' medium='image' width='1920' height='1080'><media:title type='plain'> <![CDATA[USA]]></media:title><media:thumbnail url='https://coinengineer.net/blog/wp-content/uploads/2025/08/ethereum_hack_ce.jpg' width='58' height='33' /></media:content>	</item>
	</channel>
</rss>
