Researchers have revealed that bad actors are targeting dYdX and using malicious packages to empty its user wallets. According to the report, some open source packagesResearchers have revealed that bad actors are targeting dYdX and using malicious packages to empty its user wallets. According to the report, some open source packages

Malicious packages empty dYdX user wallets

2026/02/07 18:10
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Researchers have revealed that bad actors are targeting dYdX and using malicious packages to empty its user wallets. According to the report, some open source packages published on the npm and PyPi repositories were laced with code that stole wallet credentials from dYdX developers and backend systems.

dYdX is a decentralized derivatives exchange that supports hundreds of markets for perpetual trading. In the report, researchers from security firm Socket mentioned that all the applications using the compromised npm versions are at risk. They claimed the direct impact of the attacks has included complete wallet compromise and crypto thefts. The attack scope includes all the applications that depend on the compromised version, and both developer testing with real credentials and production end-users.

Malicious packages empty dYdX user wallets

Malicious packages breach wallets associated with dYdX

According to the report, some of the packages that have been infected include npm (@dydxprotocol/v4-client-js):(3.4.1, 1.22.1, 1.15.2, 1.0.31 versions) and PyPI (dydx-v4-client): (1.1.5post1 version). Socket mentioned that the platform has processed more than $1.5 trillion in trading volume since it made its debut in the decentralized finance industry, with an average trading volume of $200 million to $540 million. In addition, the platform also has about $175 million in open interest.

The exchange provides code libraries that allow third-party applications for trading bots, automated strategies, or backend services, all of which involve mnemonics or private keys for signing. The npm malware embedded a malicious function in the legitimate package. When a seed phrase that underpins a wallet’s security is processed, the function copies it along with a fingerprint of the device running the application.

The fingerprint allows the threat actor to match stolen credentials to victims across several compromises. The domain receiving the seed phrases is dydx[.]priceoracle[.]site, which mimics the legitimate dYdX service at dydx[.]xyz through typosquatting. The malicious code available on PyPI continued the same credential theft function, although it implements a remote access Trojan (RAT) that allows execution of new malware on already infected systems.

The researchers noted that the backdoor received commands from dydx[.]priceoracle[.]site, adding that the domain was created and registered on January 9, 17 days before the malicious package was uploaded to PyPI. According to Socket, the RAT runs as a background daemon thread, beacons to the C2 server at a 10-second interval, receives Python code from the server, and executes it in an isolated subprocess with no visible output. In addition, it also uses a hard-coded authorization token.

New attack showcases disturbing trend

Socket added that once installed, the threat actors were able to carry out arbitrary Python code with user privileges, steal SSH keys, API credentials, and source code. In addition, they could also install persistent backdoors, exfiltrate sensitive files, monitor user activity, and modify critical files. The researchers added that the packages were published to npm and PyPI using official dYdX accounts, which meant they were compromised and used by the attackers.

While dYdX is yet to release a statement addressing the issue, this is at least the third time that it has been targeted in attacks. The previous incident occurred in September 2022 when a malicious code was uploaded to the npm repository. In 2024, the dYdX website was commandeered after the V3 website was hijacked through DNS. Users were redirected to a malicious website that prompted them to sign transactions designed to drain their wallets.

Socket claimed that this latest incident highlights a disturbing pattern of adversaries targeting dYdX-related assets using trusted distribution channels. It noted that the attackers knowingly compromised packages in the npm and PyPI ecosystems to expand the attack surface to reach JavaScript and Python developers working with the platform. Anyone using the platform should carefully examine all applications for dependencies on the malicious packages.

The smartest crypto minds already read our newsletter. Want in? Join them.

Market Opportunity
dYdX Logo
dYdX Price(DYDX)
$0.09787
$0.09787$0.09787
+1.78%
USD
dYdX (DYDX) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48
Mitsubishi Taps JPMorgan Kinexys As Blockchain Payments Scale

Mitsubishi Taps JPMorgan Kinexys As Blockchain Payments Scale

The post Mitsubishi Taps JPMorgan Kinexys As Blockchain Payments Scale appeared on BitcoinEthereumNews.com. Mitsubishi Corporation plans to use a blockchain-based
Share
BitcoinEthereumNews2026/03/31 13:36
BitMine’s $11B Ethereum Bet — Smart Move or Risky Gamble Before the Next Bull Run?

BitMine’s $11B Ethereum Bet — Smart Move or Risky Gamble Before the Next Bull Run?

BitMine's massive $11 billion investment in Ethereum has raised eyebrows in the crypto world. As the market eagerly awaits the next bull run, this bold move has sparked debates and curiosity. Is it a clever strategy or a high-stakes risk? Explore which coins are poised for growth in this fluctuating landscape. Ethereum Poised for Growth Amid Steady Movement Source: tradingview  Ethereum's price is steady, moving between approximately $4335 and $4825. The crypto giant is showing promise, with a week's growth of over four percent. This follows a half-year surge of nearly 127 percent. Although the current pace is slower, the potential for breaking above the $5040 resistance level is strong. If it breaches this point, Ethereum could aim for the next resistance at $5530. Such a move would be a noticeable increase from today's range, suggesting this crypto could continue its climb. The market indicators point to a balanced phase, meaning Ethereum might be setting the stage for further growth. Keep an eye on those key levels! Conclusion BitMine’s move has sparked debate. If ETH rises, the valuation could be substantial. However, market trends can change quickly. Timing and strategy will be key. BitMine’s decision shows confidence in ETH, but only time will tell if it pays off. The sector awaits the next market movement with interest. Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
Share
Coinstats2025/09/18 00:44