This story is cute: A malicious "Solidity" (that's the smart contract language Ethereum and other blockchains use) extension for Cursor, the Vibe-Coding Editor included code that steals your tokens/coins.

I find it funny for two reasons:
- Blockchainers love talking about how you need to verify things you interact with but someone wasn't checking if they have the right extension
- Programming smart contracts is hard because it's a massively hostile environment: Everyone can see your code and if you make a mistake people's assets get stolen. (every smart contract is an open bug bounty). Are we really confident that an LLM can create code up to that level of quality? Fells like it makes no sense TBH.

securelist.com/open-source-pac

0

If you have a fediverse account, you can quote this note from your own instance. Search https://tldr.nettime.org/users/tante/statuses/114868185582155409 on your instance and quote it. (Note that quoting is not supported in Mastodon.)