@1247/vampire-attack-hl
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalyscripts/analyze_hl_wallet.py
LOWAnomalyLOW
scripts/analyze_hl_wallet.py
The code functions as a reporting/analytics tool that retrieves user trading fills and price candles from an external API, computes cost and slippage metrics, and outputs structured reports. There is no evidence of malware or obfuscated code; however, the primary risk is privacy/data leakage from sending wallet addresses and trade data to a third-party API. Users should be aware of data-sharing implications, and operators should ensure API trustworthiness and provide opt-out options if needed.
Confidence: 59%Severity: 60%
Audit Metadata