SlowMist Exposes TRAE's 'Plugin Nest of Poison': Backdoor Plugins Persist, Team Silent, User Assets at Risk
Date: 2025-07-18 By William Jackson

Hook
It's 10:00 AM Zurich time. My Telegram channels light up with a single alert from SlowMist's official feed: “We have confirmed a ‘plugin nest of poison’ problem on the TRAE plugin market. Some backdoor plugins show resilience, continuously updating and iterating. Users please pay attention to the associated risks.”

That’s it. Three sentences. No fluff. No cute warnings. This is SlowMist – the same firm that traced the Poly Network hacker and audited half the DeFi summer darlings. When they drop a statement this blunt, you drop everything.
TRAE. A name you’ve probably heard whispered in Telegram groups – a plugin-based platform promising seamless DApp integration. But today, it’s not a competition. It’s a crime scene.
Chasing the alpha until the trail goes cold.
Context
Let’s back up. TRAE isn’t a Layer 1. It’s not a DeFi protocol. It’s an intermediate layer – a plugin market, think of it as an app store for blockchain interaction tools. Users install plugins to access DApps, sign transactions, or manage wallets. The promise? Convenience. The reality? A direct line to your private keys if the plugin is malicious.
This is 2025. We’ve seen it before. Back in 2020, during DeFi Summer, I watched liquidity mining farms become honeypots. But that was code exploits. This is different. This is a platform that controls the distribution of code. When the market itself is poisoned, the entire user base is a target.
SlowMist’s report doesn’t list the number of infected plugins. It doesn’t reveal the total funds stolen. But it says one terrifying thing: the backdoor plugins are updating. That means the attacker has – or had – access to the plugin update mechanism. They can push new versions, evade detection, and maintain persistence.
Core
Technical Breakdown: What “Continuous Updating” Really Means
A backdoor plugin that updates isn’t just a static piece of malware. It’s a living organism. The attacker can iterate: add new stealers, bypass antivirus rules, change C2 addresses. This implies the attacker controls the update server, or has compromised TRAE’s signing infrastructure.
From my years covering crypto security – including the 2022 Terra collapse where I wrote a psychological resilience piece – I’ve learned that “continuous iteration” is the hallmark of a professional operation. This isn’t a script kiddie. This is a team with a roadmap.
What’s at stake?
- Private keys: If a plugin can see your transaction signing, it can steal funds. Period.
- Approval exploits: Many wallets allow token approvals. A malicious plugin can drain all approved tokens.
- Data exfiltration: Browser-based plugins have access to cookies, session tokens, even passwords.
But the biggest signal? TRAE’s silence.
I’ve been in this game since ETHDenver 2017, when I snagged an off-record Vitalik comment on scalability. In security incidents, teams always respond within hours. Acknowledge. Reassure. Pledge audit. Not this time. SlowMist goes public because the team either ignored them or couldn’t fix it. That’s a death bell.
Market implications right now:
- If TRAE has a token (unconfirmed but plausible), expect a 30%+ drop within 24 hours. I’d be surprised if major exchanges don’t halt deposits.
- Users who have installed any TRAE plugin should immediately revoke all smart contract approvals via Revoke.cash, transfer funds to a fresh wallet, and reset browser settings.
- Competitors – MetaMask, Rabby, Phantom – just got a free marketing gift. Users will flee.
Contrarian Angle
Everyone is focusing on the technical vulnerability. The backdoor code. The update mechanism. But the hidden story is the silence.
In crypto, trust is earned in drops and lost in buckets. When a project goes dark during a confirmed exploit, it’s not a technical failure – it’s a governance collapse. TRAE’s team might be overwhelmed, or worse, they might be compromised. Maybe the attacker is the team. Or maybe the team is a group of anonymous devs who took the money and ran.
We saw this with the Iron Finance collapse in 2021. The team went quiet, then the founder popped up in a YouTube video crying. Silence is the loudest signal of all.
The unreported angle: This is a supply chain attack on the plugin ecosystem. If TRAE had a rigorous code review process, this wouldn’t happen. But most plugin markets rely on user reports and reactive bans. SlowMist’s warning isn’t just about TRAE – it’s an industry-wide wake-up call. Every wallet, every browser extension, every DApp store needs to implement mandatory third-party audits for every plugin before listing. And that costs money. Most projects don’t do it because they’re chasing user acquisition over security.

I’ve seen this cycle before. In 2019, I wrote about how liquidity mining APYs are subsidized – stop incentives, users vanish. The same applies here: stop treating security as a feature, and you lose everything.
Takeaway
For users: Revoke. Move. Wait. If you’ve interacted with TRAE plugins in the last month, treat your wallet as compromised. Change passwords, rotate keys, and don’t trust any TRAE-related communication.
For traders: If TRAE has a token, it’s dead money. The team’s silence means no forthcoming fix. Even if they speak tomorrow, the damage is done. Move to projects with proven security protocols.
For the industry: Watch for SlowMist’s follow-up. They’ll likely reveal specific plugin hashes or stolen amounts. That’s your second data point. Also, keep an eye on other plugin platforms – are they rushing out security updates? That’s a sign they’re nervous.
One question keeps me up: if the attacker can update plugins continuously, what else have they installed? Keyloggers? Clipboard hijackers? This rabbit hole is deep.