gdex-trading

Warn

Audited by Socket on Mar 3, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
HYPERLIQUID_DEPOSIT.md

This file is documentation and example usage, not implementation code. It does not itself contain malware, but it instructs users to provide raw private keys to an SDK and to store secrets in .env, which is a high-risk practice: if the SDK or its backend is malicious or compromised it could sign and send unauthorized transactions. Recommend treating the SDK as untrusted until its source and behavior are audited, avoid embedding private keys in environment files, and use external signing methods (hardware wallet or remote signer).

Confidence: 90%Severity: 60%
AnomalyLOW
README.md

This document is a README describing a trading bot and custodial deposit flow. It contains risky operational guidance: hardcoded example API keys and instructions to send funds to operator-controlled custodial addresses (same EVM address across chains). Those patterns present significant financial and trust risks — users surrender custody and may lose funds if the operator or backend is malicious or compromised. From this README alone there is no definitive code-level malware, but the custodial deposit design and published example credentials are dangerous in practice. Recommend: do NOT send funds to custodial addresses without auditing the codebase (src/*.ts), the gdex.pro-sdk, and the remote service operators; remove or rotate any example API keys; and require decentralized user-controlled custody patterns or audited smart contracts before depositing real funds.

Confidence: 80%Severity: 65%
Audit Metadata
Analyzed At
Mar 3, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/gemachdao%2Fgdex-trading-%2Fgdex-trading%2F@45dbbfe2ea95c45b77dcb2d41f2dbee32ee3ac1c