The post This new React bug can drain your wallets if not caught appeared on BitcoinEthereumNews.com. A critical vulnerability in React Server Components is beingThe post This new React bug can drain your wallets if not caught appeared on BitcoinEthereumNews.com. A critical vulnerability in React Server Components is being

This new React bug can drain your wallets if not caught

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A critical vulnerability in React Server Components is being actively exploited by multiple threat groups, putting thousands of websites — including crypto platforms — at immediate risk with users possibly seeing all their assets drained, if impacted.

The flaw, tracked as CVE-2025-55182 and nicknamed React2Shell, allows attackers to execute code remotely on affected servers without authentication. React’s maintainers disclosed the issue on Dec. 3 and assigned it the highest possible severity score.

Shortly after disclosure, GTIG observed widespread exploitation by both financially motivated criminals and suspected state-backed hacking groups, targeting unpatched React and Next.js applications across cloud environments.

Loading…

What the vulnerability does

React Server Components are used to run parts of a web application directly on a server instead of in a user’s browser. The vulnerability stems from how React decodes incoming requests to these server-side functions.

In simple terms, attackers can send a specially crafted web request that tricks the server into running arbitrary commands, or effectively handing over control of the system to the attacker.

The bug affects React versions 19.0 through 19.2.0, including packages used by popular frameworks such as Next.js. Merely having the vulnerable packages installed is often enough to allow exploitation.

How attackers are using it

The Google Threat Intelligence Group (GTIG) documented multiple active campaigns using the flaw to deploy malware, backdoors and crypto-mining software.

Some attackers began exploiting the flaw within days of disclosure to install Monero mining software. These attacks quietly consume server resources and electricity, generating profits for attackers while degrading system performance for victims.

Crypto platforms rely heavily on modern JavaScript frameworks such as React and Next.js, often handling wallet interactions, transaction signing and permit approvals through front-end code.

If a website is compromised, attackers can inject malicious scripts that intercept wallet interactions or redirect transactions to their own wallets— even if the underlying blockchain protocol remains secure.

That makes front-end vulnerabilities particularly dangerous for users who sign transactions through browser wallets.

Source: https://www.coindesk.com/tech/2025/12/16/new-react-bug-that-can-drain-all-your-tokens-is-impacting-thousands-of-websites

Market Opportunity
Wrapped REACT Logo
Wrapped REACT Price(REACT)
$0.01491
$0.01491$0.01491
-1.25%
USD
Wrapped REACT (REACT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Rising Binance Deposits Signal Retail Investors Are Returning

Rising Binance Deposits Signal Retail Investors Are Returning

Rising Binance Deposits Signal Retail Investors Are Returning to Crypto Markets Deposits flowing into Binance are reportedly rising sharply once again, a deve
Share
Hokanews2026/05/10 19:16
Kalshi Launches KalshiEco to Boost Prediction Market With Solana and Base

Kalshi Launches KalshiEco to Boost Prediction Market With Solana and Base

The post Kalshi Launches KalshiEco to Boost Prediction Market With Solana and Base appeared on BitcoinEthereumNews.com. On Wednesday, Kalshi introduces the KalshiEco hub with the support from Solana and Base to bolster prediction market growth. The initiative would bolster selected builders, traders, and creators with hands-on support, including grant funding, engineering assistance, referral programs, etc.  Kalshi faces legal scrutiny in Massachusetts as the firm is accused of running unlicensed sports betting under the guise of a prediction market. Kalshi, the federally regulated prediction market operator, is expanding its operations into the broader trading and builder community by introducing KalshiEco, a program that the operator is experimenting with to serve developers, traders, and creators trying on-chain and off-chain prediction market projects. The action is happening at a time when the company is under increased legal scrutiny, such as in a recent case in Massachusetts, which alleged that the company was running what state regulators term as an illegal form of sports betting. KalshiEco Ecosystem Growth The KalshiEco program is designed such that it establishes feedback between the builders and audiences. Developers are also encouraged to release new applications; creators, on the other hand, promote those tools to a wider audience, which in turn is likely to draw more attention and further development of the project. This cycle has been positioned by the company as a growth flywheel that is meant to ensure that momentum is maintained within the ecosystem. Among the selected participants, various incentives are being offered as part of the initiative. Among them, there is direct funding in the form of grants, verified badges on the social media X, individual referral programs, and engineering-specific support of projects that need more technical rigor. Other benefits are competitions in trade, branded products, and continuous community self-identification. These resources are being made by the company more as a working aid than as a marketing gift and this is…
Share
BitcoinEthereumNews2025/09/18 03:29
Planet Labs (PL) Stock Surges Over 10% Following Major Greek Satellite Deal

Planet Labs (PL) Stock Surges Over 10% Following Major Greek Satellite Deal

Planet Labs (PL) stock surged 10.78% after securing a lucrative ESA-backed satellite imagery contract with Greece through its German subsidiary. The post Planet
Share
Blockonomi2026/05/10 19:12

KAIO Global Debut

KAIO Global DebutKAIO Global Debut

Enjoy 0-fee KAIO trading and tap into the RWA boom