Developer patches wallet-drain vulnerability in AI-powered Solana trading tool BagOS
A security review revealed a two-part vulnerability in BagOS, an MCP server that lets AI agents interact with the Solana-based token launchpad Bags, which could allow a malicious repository to drain a user's crypto wallet. The attack combined a flaw where the server trusted a .env file from the working directory with a login tool that blindly signed any data it received, including full blockchain transactions. Despite 100% test coverage in CI, the flaw went undetected because coverage tracks which lines run, not which inputs are assumed safe. The developer privately drafted a security advisory, patched the bugs on a private fork, and released version 3.0.0 as a breaking change that enforces absolute config file paths and restricts the login tool to signing only Bags' exact sign-in text. All prior versions from 1.0.0 to 2.6.0 have been deprecated on npm, and the advisory has been published as GHSA-g679-3wq7-mh3m.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in