Cursor – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 13 Sep 2025 03:08:01 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Cursor – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Malicious Repos Can Trigger Auto Code Execution in Cursor AI https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/ https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/#respond Sat, 13 Sep 2025 03:08:00 +0000 https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/

Oasis Security has identified a vulnerability in Cursor, an AI-based code editor, that allows hidden code to run as soon as a user opens a project folder without any action or warning.

The issue comes from a default setting in Cursor. A safety feature called Workspace Trust is disabled by default when the program is first installed. As a result, certain task files can begin executing commands immediately when a developer opens a folder.

If a user adds a harmful task to a project and shares it online, those commands will run as soon as another person opens the folder in Cursor.

Candlesticks, Trendlines & Patterns Easily Explained (Animated Examples)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Cursor is built on top of Visual Studio Code, which also includes the Workspace Trust feature. This tool is designed to protect developers from malicious code by blocking automatic tasks from unknown sources.

The vulnerability exploits the .vscode/tasks.json file, which can contain instructions to run tasks as soon as a folder is opened. Attackers can place these instructions in a shared project.

According to Erez Schwartz from Oasis Security, this behavior can lead to stolen credentials, changed files, or system access. It also increases the chances of supply chain attacks, where malicious code spreads through tools or projects used by many people.

To stay safe, users should take a few steps. First, they should enable Workspace Trust in Cursor to stop unknown tasks from running automatically. Second, it is advised to open untrusted projects using a different code editor, especially the .vscode folder, before using Cursor.

On August 28, Anthropic warned that bad actors are using its chatbot Claude to help carry out online crimes. How? Read the full story.


]]>
https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/feed/ 0 58156
Ethereum Developer Hacked by Fake Extension on Cursor AI https://earlybirdsinvest.com/ethereum-developer-hacked-by-fake-extension-on-cursor-ai/ https://earlybirdsinvest.com/ethereum-developer-hacked-by-fake-extension-on-cursor-ai/#respond Wed, 13 Aug 2025 22:50:13 +0000 https://earlybirdsinvest.com/ethereum-developer-hacked-by-fake-extension-on-cursor-ai/

Zak Cole, a developer on Ethereum
ETH


$4,745.14

, has lost access to one of his crypto wallets after unknowingly installing a harmful browser extension.

Cole explained in an August 12 post on X that the issue began when he added an extension called “contractshark.solidity-lang” to his setup through Cursor AI.

This extension appeared safe, since it had a detailed description, a familiar icon, and had already been downloaded over 54,000 times.

What is Blockchain? (Animated Examples + Explanation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

However, after installation, the software quietly accessed Cole’s local environment file. Within minutes, his private key was copied and sent to someone else.

The extension then allowed the attacker to access Cole’s wallet for three days. On August 10, all the funds in that wallet were removed. Cole explained that he had been working to finalize a smart contract when he added the tool, which led to the oversight.

Despite the breach, Cole did not lose much money. He only stores small amounts in easily accessible wallets used for testing, while his main assets are protected with hardware devices.

His investigation led him to reports from cybersecurity sources like Kaspersky and BleepingComputer, which linked the same extension to a larger theft campaign that has taken more than $500,000 from different victims.

As of now, the extension is still available on Cursor AI’s marketplace, and the publisher remains listed as a trusted source.

Koi Security recently reported that a cybercrime group named GreedyBear has stolen more than $1 million in cryptocurrency. How? Read the full story.


]]>
https://earlybirdsinvest.com/ethereum-developer-hacked-by-fake-extension-on-cursor-ai/feed/ 0 53059
FTX Estate Fumbles $500,000,000 Investment As AI Coding Platform Cursor Now Valued at Nearly $1,000,000,000: Report https://earlybirdsinvest.com/ftx-estate-fumbles-500000000-investment-as-ai-coding-platform-cursor-now-valued-at-nearly-1000000000-report/ https://earlybirdsinvest.com/ftx-estate-fumbles-500000000-investment-as-ai-coding-platform-cursor-now-valued-at-nearly-1000000000-report/#respond Wed, 07 May 2025 05:12:24 +0000 https://earlybirdsinvest.com/ftx-estate-fumbles-500000000-investment-as-ai-coding-platform-cursor-now-valued-at-nearly-1000000000-report/

FTX bankruptcy liquidators sold its stake in the artificial intelligence (AI) coding platform Cursor for $200,000, missing a potential $500 million windfall, according to recent reports.

According to a new report from the Financial Times, Cursor – developed by Anysphere Inc. – has secured $900 million in funding at a $9 billion valuation since being sold off by FTX, with backing from prominent venture capitalist firms.

Cursor AI is a smart coding assistant that aims to enhance software development by incorporating natural language programming, advanced code suggestions, and built-in debugging. Based on a modified version of Visual Studio Code, it aims to provide deep code analysis, interactive chat support, and automated tools to help developers efficiently write, refine, and optimize their code.

The company reportedly generates more than $200 million in annual recurring revenue.

The stake originated from FTX’s trading arm, Alameda Research, which invested $200,000 in Cursor’s seed round in 2022. Liquidators sold the investment at cost, failing to anticipate the platform’s growth potential.

The sale represents another undervalued asset sale by FTX liquidators, who previously sold SUI blockchain contracts for $1 million that later reached a $3 billion valuation.

The estate continues liquidating holdings to repay customers affected by the exchange’s collapse, though the miscalculations have hampered recovery efforts.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/ftx-estate-fumbles-500000000-investment-as-ai-coding-platform-cursor-now-valued-at-nearly-1000000000-report/feed/ 0 34825