Charles Guillemet, Chief Technology Officer at Ledger, warned on Monday of a large-scale supply chain attack targeting crypto software wallets after the Node Package Manager (NPM) account of open-source developer qix was compromised.Charles Guillemet, Chief Technology Officer at Ledger, warned on Monday of a large-scale supply chain attack targeting crypto software wallets after the Node Package Manager (NPM) account of open-source developer qix was compromised.

Crypto software wallets at risk following supply chain attack

2025/09/09 08:52
3 min read
  • Ledger CTO Charles Guillemet warned of a large-scale supply chain attack that could affect software crypto wallets.
  • The warning follows reports of a reputable developer's NPM account being compromised.
  • Guillemet cautioned against performing on-chain transactions.

Charles Guillemet, Chief Technology Officer at Ledger, warned on Monday of a large-scale supply chain attack targeting crypto software wallets after the Node Package Manager (NPM) account of open-source developer qix was compromised.

Software wallets could face attacks from NPM breach

Crypto software wallets could be vulnerable to malicious attacks when performing transactions, said Guillemet in an X post on Monday.

Guillemet noted that a major supply chain attack has been underway after reputable developer qix's NPM account was compromised.

A supply chain attack targets a third-party vendor that provides services or software essential to the supply chain.

The hacked NPM was reportedly used to distribute malware designed to scan and exploit crypto wallets. Once crypto is detected, the malware alters the code responsible for signing transactions and redirects funds to addresses controlled by its creators.

"The malicious payload works by silently swapping crypto addresses on the fly to steal funds," wrote Guillemet.

NPM serves as a central registry and library for JavaScript software packages, offering command-line tools that allow developers to install and manage packages. NPM is largely used on open-source platforms and is a core part of the JavaScript ecosystem, widely relied upon for sharing and distributing code.

Guillemet added that the packages involved had been downloaded more than a billion times.

He noted that the malware poses a greater risk to software wallet users than to those with hardware wallets, urging the former to avoid making on-chain transactions.

"If you use a hardware wallet, pay attention to every transaction before signing and you're safe. If you don't use a hardware wallet, refrain from making any on-chain transactions for now," Guillemet added.

The development sparked concerns among crypto developers about the potential impact of the attacks on crypto wallets.

DefiLlama developer and pseudonymous figure Oxngmi stated on X that the supply-chain attack can only affect websites that "pushed an update since the hacked NPM package was published."

https://x.com/0xngmi/status/1965125988016087050

He reiterated Guillemet's view, stating that it is "safer to avoid using crypto websites till this blows over and they clean up the bad packages."

However, several top crypto platforms, including MetaMask wallet, Uniswap, Aave and Jupiter have stated that their systems are unaffected by the developments.

Meanwhile, Switzerland-based crypto exchange SwissBorg suffered an attack in which hackers stole 193,000 SOL, worth about $41.5 million at the time. The exchange stated that the attack involved the compromise of a partner API in its SOL Earn Program, affecting less than 1% of users.


Market Opportunity
NODE Logo
NODE Price(NODE)
$0.01427
$0.01427$0.01427
0.00%
USD
NODE (NODE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

UAE supermarket supplies remain stable, despite panic buying

UAE supermarket supplies remain stable, despite panic buying

UAE supermarkets report supplies remain ample and prices are unlikely to rise in the short term, despite fears that the widening regional conflict will cause residents
Share
Agbi2026/03/01 22:54
AUD/USD recovers early losses as US Dollar struggles to extend upside

AUD/USD recovers early losses as US Dollar struggles to extend upside

The post AUD/USD recovers early losses as US Dollar struggles to extend upside appeared on BitcoinEthereumNews.com. AUD/USD recovers its early losses as the US Dollar’s upside move seems to peak out. Investors await the Fed Powell’s speech for fresh cues on the monetary policy outlook. Australia’s Monthly CPI is expectedly to have risen steadily by 2.8%. The AUD/USD pair claws back its early losses and rebounds to near 0.6590 during the European trading session on Monday. The Aussie pair bounces back as the US Dollar (USD) struggles to extend its three-day winning streak, with investors awaiting Federal Reserve (Fed) Chair Jerome Powell’s speech on Tuesday. The US Dollar Index (DXY), which tracks the Greenback’s value against six major currencies, trades marginally lower to near 97.55. The US Dollar traded firmly in the last few days, following the monetary policy announcement by the Fed on Wednesday, in which it reduced interest rates by 25 basis points (bps) to 4.00%-25%. The Fed also signaled two more interest rate cuts in the remainder of the year. On Tuesday, investors will focus on Fed Powell’s speech to get more cues on the monetary policy meeting. Market participants would also like to know about whether the Fed will continue reducing interest rates even as inflationary pressures remain well above the central bank’s target of 2%. Meanwhile, the next trigger for the Australian Dollar (AUD) will be the Monthly Consumer Price Index (CPI) data for August, which will be published on Wednesday. The inflation data is expected to have grown steadily at an annual pace of 2.8%. Signs of inflationary pressures remaining persistent could restrict the Reserve Bank of Australia (RBA) from reduce interest rates further. US Dollar FAQs The US Dollar (USD) is the official currency of the United States of America, and the ‘de facto’ currency of a significant number of other countries where it is found in circulation alongside…
Share
BitcoinEthereumNews2025/09/22 23:57
Vitalik Buterin Says AI Could Fast Track Ethereum 2030 Roadmap

Vitalik Buterin Says AI Could Fast Track Ethereum 2030 Roadmap

TLDR AI built a 700000 line Ethereum client in two weeks Prototype covers 65 roadmap items and syncs with mainnet Buterin calls for more testing and formal verification
Share
Coincentral2026/03/01 23:01