Nofx, an AI-driven automated trading open-source project, has rapidly gained nearly 9,000 GitHub stars in just two months. However, the project is now embroiled in multiple controversies, including security vulnerabilities, team equity disputes, and open-source licensing issues. Security firm SlowMist highlighted significant risks, while internal legal conflicts among core members have surfaced. Additionally, a shift from the MIT license to AGPL has sparked compliance concerns. These events underscore systemic risks in Web3 open-source projects related to security, governance, compliance, and commercialization.