Ledger CTO cautions users to halt crypto transactions due to a mass NPM attack that hijacks wallets and loots money. The cryptocurrency world has been shaking due to a major supply chain attack that has even led the Chief Technology Officer of Ledger to make a serious warning.  Focusing on the Node Package Manager (NPM) […] The post Ledger Warns of Massive Hack, Avoid Crypto Transactions Now appeared first on Live Bitcoin News.Ledger CTO cautions users to halt crypto transactions due to a mass NPM attack that hijacks wallets and loots money. The cryptocurrency world has been shaking due to a major supply chain attack that has even led the Chief Technology Officer of Ledger to make a serious warning.  Focusing on the Node Package Manager (NPM) […] The post Ledger Warns of Massive Hack, Avoid Crypto Transactions Now appeared first on Live Bitcoin News.

Ledger Warns of Massive Hack, Avoid Crypto Transactions Now

2025/09/10 14:00
3 min read

Ledger CTO cautions users to halt crypto transactions due to a mass NPM attack that hijacks wallets and loots money.

The cryptocurrency world has been shaking due to a major supply chain attack that has even led the Chief Technology Officer of Ledger to make a serious warning. 

Focusing on the Node Package Manager (NPM) ecosystem, the attack uses malicious code that silently replaces the cryptocurrency wallet addresses on transactions. 

Users also have the risk of losing their funds to attackers without their notice. The Ledger CTO advises against cryptocurrency transactions until the risk of theft is gone.

NPM Compromise of Cryptocurrency Wallets

A phishing assault compromised developer qix’s NPM account, allowing hackers to inject malicious code into dozens of popular JavaScript packages, including chalk and strip-ansi. The scope is enormous since these packages have more than a billion downloads every week.

The malware injected serves as a crypto-clipper, which captures Web3 transactions in browsers. 

It overwrites authentic wallet addresses in near real time with those of the attacker. This complicates the detection of fraudulent transactions by users to a great extent.

Ledger CTO Warns of Caution on Crito Dealings

This risk was noted by Charles Guillemet, the CTO of Ledger, on the social platform X. He emphasized that the users of hardware wallets featuring clear signing ability are able to verify transaction addresses safely and are therefore less prone. 

Nevertheless, software wallet users are at a high risk and should not sign any on-chain transactions until the matter is completely addressed.

He said that users who do not have hardware wallets are at high risk since they cannot precisely confirm transaction details. 

The forewarning cuts across various blockchains such as Ethereum, Solana, and Bitcoin, among other blockchains that have already fallen prey to the malware.

The Malware Mechanism: Two-Pronged Attack

Source – substack.com 

Analysts who examined the code have identified two significant attack vectors. To begin with, an inactive approach in which the code monkey-patches fetch and XMLHttpRequest functions of browsers and replaces wallet addresses with similar but fraudulent addresses. 

It applies advanced algorithms to make the replaced addresses appear almost the same, which deceives users with ease.

Second, in case a wallet like MetaMask is detected, the malware blocks request transactions and modifies recipient addresses prior to user authentication. 

Users who fail to meticulously pay attention to the signing process of documents, unwillingly grant transfer authority to hackers.

Large Scale Effect on the JavaScript Ecosystem

This attack impacts vital development packages that are utilized worldwide in web and crypto applications. Besides, chalk and strip-ansi, color-convert, error-ex, and has-ansi were compromised.

The attack highlights vulnerabilities in software supply chains, particularly in open-source ecosystems that are part and parcel of blockchain and crypto services.

Users and developers are encouraged to audit dependencies, pin safe package versions, and update lockfiles, lest they pull malicious code.

The sources affirm that although most of the contaminated packages were cleaned, scientists are keeping an eye on the remaining infected versions. 

The attack is one of the worst related to crypto in history yet it has resulted in greater awareness and quicker remediation.

Ledger is telling the truth: he says not to have any crypto-transactions without secure hardware wallets with transparent signing. 

This is a radical recommendation that will help defend digital assets against the unknown yet notable threat that is looming through the software supply chain.

Market Opportunity
NODE Logo
NODE Price(NODE)
$0.01586
$0.01586$0.01586
+0.12%
USD
NODE (NODE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump will never allow a MAGA defeat - and the implications are unthinkable

Trump will never allow a MAGA defeat - and the implications are unthinkable

Last Aug. 18, Donald Trump sat across from Ukrainian President Volodymyr Zelensky in the Oval Office and posed a “question” that seemed, at the time, like nothing
Share
Rawstory2026/02/07 21:10
A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Share
BitcoinEthereumNews2025/09/18 02:23
Ozak AI Presale Moves Into Phase 6 With Price Reaching $0.012, Gains Top 1,100%

Ozak AI Presale Moves Into Phase 6 With Price Reaching $0.012, Gains Top 1,100%

The Ozak AI presale has officially entered Phase 6, pushing the token price to $0.012. The project has already provided over 1,100 percent returns to the first-round investors who have invested in it since its initial days. Over 902 million tokens have been sold, and over $3.2 million has been raised. The next phase will […] The post Ozak AI Presale Moves Into Phase 6 With Price Reaching $0.012, Gains Top 1,100%  appeared first on Live Bitcoin News.
Share
LiveBitcoinNews2025/09/18 20:00