Back to advisories

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Malicious VS Code extensions named 'Solidity Pro' are stealing crypto wallets, API keys, and credentials from developers. The malware uses obfuscation and delayed activation to avoid detection, exfiltrating data via Telegram. Any developer who installed these extensions has exposed sensitive credentials and should be treated as compromised.

CRITICALAdvisoryAug 10, 2026
Action required
Immediately audit all developer workstations for installed Solidity Pro extensions. Force uninstall, reset all API keys and crypto wallet credentials, and scan endpoint activity logs for data exfiltration to Telegram IPs/domains.
Affected products
Solidity ProVisual Studio CodeMicrosoftLumma Stealer