Ledger's CTO Charles Guillemet warned of a large-scale supply chain attack, potentially stealing crypto from common software wallets. Crypto experts warned users to avoid transactions until the situation clears.Ledger's CTO Charles Guillemet warned of a large-scale supply chain attack, potentially stealing crypto from common software wallets. Crypto experts warned users to avoid transactions until the situation clears.

Ledger CTO warns of massive supply attack targeting crypto users

A widespread supply chain attack has been discovered, potentially tracking data from a crypto wallet and stealing assets on all chains. The npm library of a big and trusted account has been compromised, researchers announced. 

A widespread npm supply chain attack is potentially targeting the owners of the most common crypto wallets. Charles Guillemet, CTO of Ledger, warned users to avoid crypto transactions using common browser-based or desktop wallets, and only transact through hardware wallets with great caution. 

Researchers discovered one of the trusted JavaScript npm accounts was spreading packages with malicious code that was able to track and even divert crypto transactions. Soon after the attack, the maintainer reached out to the community via a Hackernoon profile to warn that the affected packages are still mostly compromised and yet to be replaced with safe versions.

The npm maintainer’s account is still not recovered, and was most probably stolen through social engineering and a fake 2FA process. GitHub users reported a suspicious email originating from npmjs support. 

Ledger CTO Charles Guillemet: avoid crypto transactions, supply chain attack discoveredOne of the JavaScript npm maintainers received a fake support email, leading to a compromised account and malicious crypto-stealing code injection into JavaScript packages. | Source: GitHub

The current event is viewed as the largest npm supply chain attack in history. More suppliers can be compromised if the emails manage to steal other accounts.

Large-scale supply chain attack targets software crypto wallets

In the past week, Cryptopolitan reported on two packages being compromised to steal crypto on Ethereum. 

The current attack is much larger – affecting a total of 18 highly popular npm packages, with 2B downloads in the past week. At this point, it is uncertain how many of the packages have spread through the JavaScript ecosystem. 

The supply chain attack is considered one of the biggest threats in the crypto space, potentially changing the destination of funds on the fly, despite the user seemingly signing the correct transaction. 

Once again, the biggest threat is against software wallet users, reportedly affecting MetaMask, Trust Wallet, Exodus, and others. All npm packages have been disabled, but developers must return to their code to discontinue the usage of the flawed packages. 

Hours after the attack, Axiom and Jupiter DEX confirmed they did not use any of the flawed npm packages and trading can continue. Kamino also reported it has not deployed any flawed code.

Users urged to avoid signing transactions until developers give a green light

For now, it is considered improbable that the attacker is capable of stealing private seeds directly, as it would expose even bigger problems with wallet security. Currently, user wallets are safe unless they send out or sign a transaction. 

The address swap happens before signing, as the attacker uses similar-looking destination wallets. The addresses look almost similar, requiring a detailed letter-by-letter verification before signing. Usually, crypto users check only the first and last four digits, leaving them open to address swap attacks. 

However, there are also smart contracts and automated transactions. End users are advised to lock and disable all browser wallets and refrain from signing transactions. The news also did not break down Monday’s crypto rally. Additionally, on-chain detectives have not sent out warnings of big or unusual losses from individual wallets.

The attack can affect all apps in the Web3 and DeFi ecosystem. Currently, transactions continue on all chains. Researchers have taken a screengrab of potential destination wallets, some of which are still empty. 

KEY Difference Wire: the secret tool crypto projects use to get guaranteed media coverage

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

USD/INR opens flat on hopes of RBI’s follow-through intervention

USD/INR opens flat on hopes of RBI’s follow-through intervention

The post USD/INR opens flat on hopes of RBI’s follow-through intervention appeared on BitcoinEthereumNews.com. The Indian Rupee (INR) opens on a flat note against
Share
BitcoinEthereumNews2025/12/18 13:33
A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Share
BitcoinEthereumNews2025/09/18 02:23
US and UK Set to Seal Landmark Crypto Cooperation Deal

US and UK Set to Seal Landmark Crypto Cooperation Deal

The United States and the United Kingdom are preparing to announce a new agreement on digital assets, with a focus on stablecoins, following high-level talks between senior officials and major industry players.
Share
Cryptodaily2025/09/18 00:49