---
title: "Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials | SpinGraph: Bad-actor framing"
description: "SpinGraph analysis of The Hacker News's Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials story: bad-actor framing, The Shield, S…"
	canonical: "https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials"
html: "https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials"
json: "https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials.json"
markdown: "https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials.md"
keywords: ["VS Code", "Solidity", "credential theft", "The Shield", "narrative intelligence"]
date: "2026-08-10T07:38:23+00:00"
modified: "2026-08-10T13:26:41.714661+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Know the moment AI knows your story. Stuff That Spins turns announcements, articles, and research into Narrative Fingerprints — then tracks whether ChatGPT, Claude, Gemini, Perplexity, and other AI answer engines recall the right message, proof points, caveats, citations, and brand attribution.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials#article","headline":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials","alternativeHeadline":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials | SpinGraph: Bad-actor framing","description":"SpinGraph analysis of The Hacker News's Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials story: bad-actor framing, The Shield, S…","datePublished":"2026-08-10T07:38:23+00:00","dateModified":"2026-08-10T13:26:41.714661+00:00","url":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"VS Code, Solidity, credential theft, malware, Open VSX","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html","about":[{"@type":"Thing","name":"VS Code"},{"@type":"Thing","name":"Solidity"},{"@type":"Thing","name":"credential theft"},{"@type":"Thing","name":"malware"},{"@type":"Thing","name":"Open VSX"},{"@type":"Product","name":"Solidity Pro","url":"https://stuffthatspins.com/entities/solidity-pro"}],"mentions":[{"@type":"Organization","name":"The Hacker News"}],"abstract":"Malicious VS Code extensions 'solidity-pro' distributed credential-stealing malware Extensions used deceptive naming to mimic legitimate Solidity tooling Removed from Open VSX but GitHub repository remains accessible"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials","item":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials#spin-analysis","headline":"Spin Analysis: bad-actor framing","description":"Emphasizes actor malice while minimizing platform governance gaps, vetting failures, or systemic risks in extension marketplaces; omits responsibility for detection latency or repository persistence.","about":{"@type":"DefinedTerm","name":"bad-actor framing","description":"Cybersecurity alert focused on attribution to bad actors rather than systemic vulnerability or accountability.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":40,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Malicious VS Code extensions named 'solidity-pro' stole crypto wallets and credentials."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Cybersecurity alert focused on attribution to bad actors rather than systemic vulnerability or accountability."},{"@type":"PropertyValue","name":"Missing Context","value":"No details on Open VSX or GitHub moderation response timelines; No disclosure of whether affected users were notified; No analysis of how the extensions evaded prior detection"},{"@type":"PropertyValue","name":"How the Spin Works","value":"Combines researcher authority signals with precise naming and removal status to create an impression of contained, attributable harm — but avoids examining why the extensions passed initial listing, how long they persisted, or what safeguards failed, thereby shrinking perceived platform responsibility relative to the actual attack surface."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer.","appearance":"Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ('solidity-pro') that has been observed delivering a browser wallet and credential stealer.","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"malicious extensions","value":"2","description":"helper-beeps.solidity-pro and web3devtoolsx.solidity-pro"}]}]}
---

# Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

**Source:** Unknown  
**Published:** August 10, 2026  
**Original:** https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Two malicious VS Code extensions named 'solidity-pro' were identified as delivering browser wallet and credential-stealing malware, though they have since been removed from Open VSX.

### TL;DR

- Malicious VS Code extensions 'solidity-pro' distributed credential-stealing malware
- Extensions used deceptive naming to mimic legitimate Solidity tooling
- Removed from Open VSX but GitHub repository remains accessible

### Key Stats

- **2** — malicious extensions. helper-beeps.solidity-pro and web3devtoolsx.solidity-pro

<a id="spingraph"></a>

## SpinGraph

The story focuses blame on the attackers behind the extensions, making it easier to overlook how easily such malware slipped through official channels and remained available long enough to pose risk.

- **Claim:** Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Citation, reputation, and authority as threat identifiers
- **Gap:** No details on Open VSX or GitHub moderation response timelines
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 40%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The story focuses blame on the attackers behind the extensions, making it easier to overlook how easily such malware slipped through official channels and remained available long enough to pose risk.

**What the story wants you to believe:** The threat came solely from identifiable bad actors, not from systemic weaknesses in extension distribution platforms or developer tooling ecosystems.  

**What it makes harder to question:** Platform accountability for vetting, monitoring, or rapid takedown of malicious extensions.  

**How the Spin Works:** Combines researcher authority signals with precise naming and removal status to create an impression of contained, attributable harm — but avoids examining why the extensions passed initial listing, how long they persisted, or what safeguards failed, thereby shrinking perceived platform responsibility relative to the actual attack surface.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “No details on Open VSX or GitHub moderation response timelines”?
- Why does the main frame leave this out: “No disclosure of whether affected users were notified”?

### Who Benefits If This Frame Spreads

- **Cybersecurity researchers** — Citation, reputation, and authority as threat identifiers _(Framing positions them as vigilant discoverers protecting developers, reinforcing their role as essential gatekeepers.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** bad-actor framing  
**Category:** The Shield  
**Spin Score:** 40%  

Emphasizes actor malice while minimizing platform governance gaps, vetting failures, or systemic risks in extension marketplaces; omits responsibility for detection latency or repository persistence.

**Who Benefits If This Frame Spreads:** Cybersecurity researchers gain credibility and visibility by flagging the threat.

**The Frame:** Cybersecurity alert focused on attribution to bad actors rather than systemic vulnerability or accountability.

### Missing Context

- No details on Open VSX or GitHub moderation response timelines
- No disclosure of whether affected users were notified
- No analysis of how the extensions evaded prior detection

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** malicious, flagged, steal, observed delivering

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Reports presence and behavior of two named extensions with observed malware delivery, but provides no technical artifacts (hashes, IOC, network logs) or independent validation of payload behavior.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
Could backfire if downstream reporting misattributes blame to Solidity tooling broadly or if affected users discover delayed remediation or lack of user notifications.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Malicious VS Code extensions named 'solidity-pro' stole crypto wallets and credentials.  
AI may drop the nuance that only two specific extensions were implicated, conflating them with legitimate Solidity tooling or implying broader ecosystem compromise.  
**Counter-Frame (Media):** May reframe as evidence of lax VS Code marketplace governance or insufficient developer education on extension hygiene.  
**Missing Voices:** Open VSX maintainers, GitHub policy team, Affected developers  

### Questions Not Answered

- When were the extensions first published or active?
- How many users installed them before removal?
- What specific APIs or wallets were targeted and compromised?

## Narrative Entities

- [Solidity Pro](https://stuffthatspins.com/entities/solidity-pro) (product — malicious VS Code extension)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (product)

Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Attribution to researchers and description of observed behavior  
> Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ('solidity-pro') that has been observed delivering a browser wallet and credential stealer.

**Evidence Gaps:** Binary hashes; Network traffic indicators; Independent replication of payload execution; Timeline of discovery-to-removal  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 10, 2026  
- **SpinGraph summary:** Attributes harm to external malicious actors (unidentified extension publishers), positioning platform maintainers (VS Code, Open VSX) and tooling ecosystem as victims or reactive defenders.  
- **Likely AI summary:** Malicious VS Code extensions named 'solidity-pro' stole crypto wallets and credentials.  

## Citation Summary

This page documents a verified instance of supply-chain compromise via malicious IDE extensions targeting blockchain developers — critical for threat intelligence and secure development practice guidance.

---
*HTML version: https://stuffthatspins.com/spin/solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials*
