【Ethereum core developer's cryptocurrency wallet stolen by malicious AI extension】Golden Finance reports that Ethereum core developer Zak Cole claimed in a post on the X platform on Tuesday that he became a victim of a malicious AI extension called Cursor AI, which allowed attackers to gain access to his hot wallet within three days and ultimately transferred funds. The developer installed a plugin named 'contractshark.solidity-lang', which appeared to be legitimate—complete with a professional icon, descriptive text, and over 54,000 downloads—but secretly stole his private key. Cole stated that this plugin 'read my .env file' and sent the private key to the attacker's server, allowing the attacker access to his hot wallet for three days before transferring funds on August 10.