The post how crypto’s ‘largest supply chain attack’ stole just $0.05 appeared on BitcoinEthereumNews.com. A widespread security supply chain attack led to panic across the crypto community yesterday with users warned to “refrain from making any on-chain transactions.” Researchers at security firm Aikido raised the alarm after discovering that 18 popular node package manager (npm) packages contained malicious code. After being notified, the developer who maintains the popular npm packages, alias Qix, confirmed the compromise. He’d been “pwned” via a phishing email which “looked very legitimate.” Despite the packages being widespread across the crypto industry, the attack led to almost no losses. Samczsun, the head of Security Alliance, a blockchain security collective, called the result a “generational fumble.” my sincerest condolences to the person responsible for this, this was a generational fumble, the likes of which we will probably never see again https://t.co/nfiTU5K0Ig — samczsun (@samczsun) September 8, 2025 Read more: ‘Decentralized’ apps suffer after Ledger Connect Kit attack What is an npm compromise? While short-lived, the compromise was far reaching, due to the sheer frequency at which packages such as “chalk” and “debug-js” are used. Analysis of the incident by Security Alliance stated that the compromised packages total “over 2 billion downloads per week.” It called the incident “likely the largest supply chain attack in history.” In theory, the compromised packages could be used to modify transaction data for crypto users. The Aikido report explains how the code “intercepts crypto and web3 activity in the browser” before it “rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user.” In an effort to camouflage the substituted addresses, the code uses the Levenshtein distance algorithm. This identifies visually similar attacker-controlled addresses to be injected in each attack. The technique is similar to the often costly address poisoning attacks which plague the industry. So, was the… The post how crypto’s ‘largest supply chain attack’ stole just $0.05 appeared on BitcoinEthereumNews.com. A widespread security supply chain attack led to panic across the crypto community yesterday with users warned to “refrain from making any on-chain transactions.” Researchers at security firm Aikido raised the alarm after discovering that 18 popular node package manager (npm) packages contained malicious code. After being notified, the developer who maintains the popular npm packages, alias Qix, confirmed the compromise. He’d been “pwned” via a phishing email which “looked very legitimate.” Despite the packages being widespread across the crypto industry, the attack led to almost no losses. Samczsun, the head of Security Alliance, a blockchain security collective, called the result a “generational fumble.” my sincerest condolences to the person responsible for this, this was a generational fumble, the likes of which we will probably never see again https://t.co/nfiTU5K0Ig — samczsun (@samczsun) September 8, 2025 Read more: ‘Decentralized’ apps suffer after Ledger Connect Kit attack What is an npm compromise? While short-lived, the compromise was far reaching, due to the sheer frequency at which packages such as “chalk” and “debug-js” are used. Analysis of the incident by Security Alliance stated that the compromised packages total “over 2 billion downloads per week.” It called the incident “likely the largest supply chain attack in history.” In theory, the compromised packages could be used to modify transaction data for crypto users. The Aikido report explains how the code “intercepts crypto and web3 activity in the browser” before it “rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user.” In an effort to camouflage the substituted addresses, the code uses the Levenshtein distance algorithm. This identifies visually similar attacker-controlled addresses to be injected in each attack. The technique is similar to the often costly address poisoning attacks which plague the industry. So, was the…

how crypto’s ‘largest supply chain attack’ stole just $0.05

A widespread security supply chain attack led to panic across the crypto community yesterday with users warned to “refrain from making any on-chain transactions.”

Researchers at security firm Aikido raised the alarm after discovering that 18 popular node package manager (npm) packages contained malicious code.

After being notified, the developer who maintains the popular npm packages, alias Qix, confirmed the compromise. He’d been “pwned” via a phishing email which “looked very legitimate.”

Despite the packages being widespread across the crypto industry, the attack led to almost no losses.

Samczsun, the head of Security Alliance, a blockchain security collective, called the result a “generational fumble.”

Read more: ‘Decentralized’ apps suffer after Ledger Connect Kit attack

What is an npm compromise?

While short-lived, the compromise was far reaching, due to the sheer frequency at which packages such as “chalk” and “debug-js” are used.

Analysis of the incident by Security Alliance stated that the compromised packages total “over 2 billion downloads per week.” It called the incident “likely the largest supply chain attack in history.”

In theory, the compromised packages could be used to modify transaction data for crypto users.

The Aikido report explains how the code “intercepts crypto and web3 activity in the browser” before it “rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user.”

In an effort to camouflage the substituted addresses, the code uses the Levenshtein distance algorithm. This identifies visually similar attacker-controlled addresses to be injected in each attack.

The technique is similar to the often costly address poisoning attacks which plague the industry.

So, was the panic justified?

Warnings came in many forms. Some opted for measured recommendations to avoid signing transactions. Others made tongue in cheek claims that “THE BLOCKCHAIN IS COMPROMISED.”

Read more: Starknet stutters, turns off and on again twice in one day

MetaMask, crypto’s most popular browser wallet, took to X to reassure users not to be “scared” of the attack. They detailed three “layers of defense” in place “to protect our products and users.”

0xngmi, the pseudonymous developer of decentralized finance dashboard DeFiLlama, explained that malicious packages would “only impact websites that pushed an update since the hacked npm package was published,” adding “most projects pin their dependencies, so even if they push an update they’ll keep using the old safe code.”

In all, the compromised packages were up for around two and a half hours. While the issue is marked as resolved on GitHub, Qix warns “other maintainers have been affected. Stay vigilant.”

The ‘dust’ settles

Once it became clear that the danger was limited, the community turned its focus to the attacker’s addresses.

Security Alliance identified a grand total of “around five cents of ETH” directly stolen during the attack.

Etherscan data show that the main address’ holdings are worth just over $900. However, around half that is 0.1 ETH, sent this morning, and various memecoins transferred for visibility.

Ridicule even came on-chain with one transaction input data message calling the attacker a “bloody fool.” The user made fun of the hacker who “hacked a massive npm developer account and still [couldn’t] steal [a] single penny. You are such a looser [sic].”

Security researchers took a moment to reflect, worrying that the bungled attempt may have “shown the way” for copycats.

Read more: The solution to crypto’s Lazarus problem could be simpler than expected

The Security Alliance X account says the industry “got lucky.” A “stealthily deployed backdoor” targeting developers could have persisted for long enough to be integrated into crypto apps.

Its incident report points to the true cost as the wasted “hours spent by engineering and security teams” and the “sales contracts that will inevitably be signed as a result of this new case study.”

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/explained-how-cryptos-largest-supply-chain-hack-stole-just-0-05/

Market Opportunity
DAR Open Network Logo
DAR Open Network Price(D)
$0.01292
$0.01292$0.01292
-7.38%
USD
DAR Open Network (D) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Mitosis Price Flashes a Massive Breakout Hope; Cup-And-Handle Pattern Signals MITO Targeting 50% Rally To $0.115305 Level

Mitosis Price Flashes a Massive Breakout Hope; Cup-And-Handle Pattern Signals MITO Targeting 50% Rally To $0.115305 Level

The analyst identified a formation of a cup-and-handle pattern on Mitosis’s chart, suggesting that MITO is preparing to see a looming price explosion.
Share
Blockchainreporter2026/01/18 09:00
Spot ETH ETFs Surge: Remarkable $48M Inflow Streak Continues

Spot ETH ETFs Surge: Remarkable $48M Inflow Streak Continues

BitcoinWorld Spot ETH ETFs Surge: Remarkable $48M Inflow Streak Continues The cryptocurrency world is buzzing with exciting news as Spot ETH ETFs continue to capture significant investor attention. For the second consecutive day, these innovative investment vehicles have seen substantial positive flows, reinforcing confidence in the Ethereum ecosystem. This consistent performance signals a growing appetite for regulated crypto exposure among traditional investors. What’s Fueling the Latest Spot ETH ETF Inflows? On September 19, U.S. Spot ETH ETFs collectively recorded a net inflow of an impressive $48 million. This marked another day of positive momentum, building on previous gains. Such figures are not just numbers; they represent tangible capital moving into the Ethereum market through accessible investment products. BlackRock’s ETHA Leads the Charge: A standout performer was BlackRock’s ETHA, which alone attracted a staggering $140 million in inflows. This substantial figure highlights the significant influence of major financial institutions in driving the adoption of crypto-backed ETFs. Institutional Confidence: The consistent inflows, particularly from prominent asset managers like BlackRock, suggest increasing institutional comfort and conviction in Ethereum’s long-term potential. Why Are Consecutive Spot ETH ETF Inflows So Significant? Two consecutive days of net inflows into Spot ETH ETFs are more than just a fleeting trend; they indicate a strengthening pattern of investor interest. This sustained positive movement suggests that initial hesitancy might be giving way to broader acceptance and strategic positioning within the digital asset space. Understanding the implications of these inflows is crucial: Market Validation: Continuous inflows serve as a strong validation for Ethereum as a legitimate and valuable asset class within traditional finance. Liquidity and Stability: Increased capital flowing into these ETFs can contribute to greater market liquidity and potentially enhance price stability for Ethereum itself, reducing volatility over time. Paving the Way: The success of Spot ETH ETFs could also pave the way for other cryptocurrency-based investment products, further integrating digital assets into mainstream financial portfolios. Are All Spot ETH ETFs Experiencing the Same Momentum? While the overall picture for Spot ETH ETFs is overwhelmingly positive, it’s important to note that individual fund performances can vary. The market is dynamic, and different funds may experience unique flow patterns based on investor preferences, fund structure, and underlying strategies. Mixed Performance: On the same day, Fidelity’s FETH saw net outflows of $53.4 million, and Grayscale’s Mini ETH recorded outflows of $11.3 million. Normal Market Fluctuations: These outflows, while notable, are a normal part of market dynamics. Investors might be rebalancing portfolios, taking profits, or shifting capital between different investment vehicles. The net positive inflow across the entire sector indicates that new money is still entering faster than it is leaving. This nuanced view helps us appreciate the complex interplay of forces shaping the market for Spot ETH ETFs. What’s Next for Spot ETH ETFs and the Ethereum Market? The sustained interest in Spot ETH ETFs suggests a potentially bright future for Ethereum’s integration into traditional financial markets. As more investors gain access to ETH through regulated products, the demand for the underlying asset could increase, influencing its price and overall market capitalization. For investors looking to navigate this evolving landscape, here are some actionable insights: Stay Informed: Keep an eye on daily inflow and outflow data, as these can provide early indicators of market sentiment. Understand Diversification: While Spot ETH ETFs offer exposure, remember the importance of a diversified investment portfolio. Monitor Regulatory Developments: The regulatory environment for cryptocurrencies is constantly evolving, which can impact the performance and availability of these investment products. Conclusion: A Promising Horizon for Ethereum The consistent positive net inflows into Spot ETH ETFs for a second straight day underscore a significant shift in how institutional and retail investors view Ethereum. This growing confidence, spearheaded by major players like BlackRock, signals a maturing market where digital assets are increasingly seen as viable components of a modern investment strategy. As the ecosystem continues to develop, these ETFs will likely play a crucial role in shaping Ethereum’s future trajectory and its broader acceptance in global finance. It’s an exciting time to watch the evolution of these groundbreaking financial instruments. Frequently Asked Questions (FAQs) Q1: What is a Spot ETH ETF? A Spot ETH ETF (Exchange-Traded Fund) is an investment product that directly holds Ethereum. It allows investors to gain exposure to Ethereum’s price movements without needing to buy, store, or manage the actual cryptocurrency themselves. Q2: Why are these recent inflows into Spot ETH ETFs important? The recent inflows signify growing institutional and retail investor confidence in Ethereum as an asset. Consistent positive flows can lead to increased market liquidity, potential price stability, and broader acceptance of cryptocurrencies in traditional financial portfolios. Q3: Which funds are leading the inflows for Spot ETH ETFs? On September 19, BlackRock’s ETHA led the group with a substantial $140 million in inflows, demonstrating strong interest from a major financial institution. Q4: Do all Spot ETH ETFs experience inflows simultaneously? No, not all Spot ETH ETFs experience inflows at the same time. While the overall sector may see net positive flows, individual funds like Fidelity’s FETH and Grayscale’s Mini ETH can experience outflows due to various factors such as rebalancing or profit-taking by investors. Q5: What does the success of Spot ETH ETFs mean for Ethereum’s price? Increased demand through Spot ETH ETFs can potentially drive up the price of Ethereum by increasing buying pressure on the underlying asset. However, numerous factors influence crypto prices, so it’s not a guaranteed outcome. If you found this article insightful, consider sharing it with your network! Your support helps us continue to provide valuable insights into the dynamic world of cryptocurrency. Spread the word and help others understand the exciting developments in Spot ETH ETFs! To learn more about the latest crypto market trends, explore our article on key developments shaping Ethereum institutional adoption. This post Spot ETH ETFs Surge: Remarkable $48M Inflow Streak Continues first appeared on BitcoinWorld.
Share
Coinstats2025/09/20 11:10
Trump imposes 10% tariffs on eight European countries over Greenland.

Trump imposes 10% tariffs on eight European countries over Greenland.

PANews reported on January 18th that, according to Jinshi News, on January 17th local time, US President Trump announced via social media that, due to the Greenland
Share
PANews2026/01/18 08:46