< Back to all clusters
[TECHNOLOGY] · South Korea · 4 sources

started · updated

Bithumb warns of malware disguised as AI trading tools

Bithumb has launched a security campaign to warn users about malicious software disguised as artificial intelligence (AI) automated trading programs and investment analysis tools. Cybercriminals are reportedly using deceptive marketing—promising high returns or loss-free trading via API connections—to lure users into downloading unauthorized executable (.exe) or compressed (.zip) files through search ads, social media, and messenger links.

If infected, these programs can steal browser-stored credentials, login session cookies, API keys, and sensitive private wallet information, including private keys and seed phrases. Attackers may use stolen login sessions to access accounts without passwords or exploit API permissions to conduct unauthorized trades.

Bithumb advises users to avoid downloading unauthorized programs from unverified sources and recommends using official services like the ‘Bithumb AI TradeKit.’ To mitigate risk, the exchange suggests issuing API keys with minimal permissions—excluding withdrawal rights—and immediately discarding any exposed or unused keys. If infection is suspected, users should disconnect from the internet and change passwords using a separate, uninfected device.

Entities

Bithumb