[Photo: Bithumb]

Bithumb is moving to prevent damage from malware disguised as artificial intelligence (AI) auto-trading programs or investment analysis tools.

Bithumb said on Wednesday it will run a malware damage prevention campaign using "fake AI auto-trading programs and investment analysis tools" as part of its September cybersecurity campaign.

As digital asset investment services that incorporate AI technology spread, cybercrime exploiting them is also increasing, the company said.

Fraudsters lure users with claims such as "AI trades automatically for high returns" and "Connect only an API key to enable loss-free auto-trading." They then use tactics to induce installation of unauthorised programs containing malware.

If infected, user IDs and passwords saved in a browser, login session cookies, as well as API keys and a personal wallet's private key, and seed phrases can be leaked.

If an attacker uses a stolen login session, it may be possible to access an account without entering a password. The attacker may also abuse API key permissions for unauthorised trading.

Bithumb urged users not to download unauthorised AI programs from unclear sources and to use official verification channels. It said users should be especially cautious about installing executable files (.exe) or compressed files (.zip) distributed through search ads, social networking services (SNS) or messenger links.

If using an AI auto-trading service, it recommended using services such as Bithumb's officially provided "Bithumb AI TradeKit (AI TradeKit)."

Bithumb AI TradeKit is operated with a structure that does not separately store API key-related information on a user's device. It can be linked with AI services such as ChatGPT and Claude to use 24-hour automated trading without separate coding.

It also stressed management of security information. It said information related to asset access permissions, such as API keys, private keys and seed phrases, must not be entered directly into external unauthorised programs or websites, or AI services.

It said that even when issuing an API key to link to an auto-trading service, it is safer not to grant withdrawal permissions and to set only necessary permissions such as viewing and ordering. It recommended immediately discarding keys that are unused or exposed externally.

If an unknown browser extension appears after installing an unauthorised program or if an alert appears about changes to security settings, users should check the possibility of malware infection.

If infection is suspected, users should cut the internet connection and use a separate, uninfected device to take account protection steps such as changing the Bithumb password, deleting API keys and checking the withdrawal address list.

A Bithumb official said, "Information-stealing unauthorised malware abusing AI is rampant, so caution is needed." The official added, "We will continue to strengthen our security systems and expand prevention campaigns."

Keyword

#Bithumb #AI TradeKit #API Key #ChatGPT #Claude
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.