The post Crypto Funds at Risk from Massive Supply Chain Attack appeared on BitcoinEthereumNews.com. Crypto Hack: What Happened? A widely used npm package, error-ex, was tampered with in its 1.3.3 release. Hidden inside was obfuscated code that activates two dangerous attack modes: Clipboard Hijacking: When you paste a wallet address, the malware silently swaps it with the attacker’s lookalike address. Transaction Interception: If you use a browser wallet, the code can intercept transaction calls and change the recipient’s address before you even see the confirmation screen. This makes it nearly impossible to notice unless you carefully check every single character of the address you’re sending to. Who’s at Risk from this Crypto Hack? Developers: Any project pulling dependencies without strict version pinning may have installed the infected version. This could affect CI pipelines, production builds, and apps that rely on JavaScript. Crypto Users: The malware targets major assets including $BTC, $ETH, $SOL, $TRX, $LTC, and $BCH. Both clipboard users and browser wallets are at risk. Platforms: Even centralized apps integrating npm libraries may have unknowingly included the malicious code. Which Companies were Affected? Already, SwissBorg confirmed a breach linked to a compromised partner API. Roughly 192.6K SOL (~$41.5M) was drained in the attack. While the SwissBorg app itself remains secure, its SOL Earn Program was hit, affecting <1% of users. The platform has promised recovery measures, including treasury funds and support from white-hat hackers. How to Protect Yourself Here’s what you need to do right now: For Wallet Users ✅ Always verify every transaction — check the full recipient address before signing.✅ Use a hardware wallet with clear signing enabled.✅ Avoid unnecessary browser wallet extensions.✅ If something feels off (unexpected signing requests), close the tab immediately. For Developers ⚙️ Switch CI builds from npm install to npm ci to lock dependencies.⚙️ Run npm ls error-ex to detect infected installs.⚙️ Pin safe versions (error-ex@1.3.2) and… The post Crypto Funds at Risk from Massive Supply Chain Attack appeared on BitcoinEthereumNews.com. Crypto Hack: What Happened? A widely used npm package, error-ex, was tampered with in its 1.3.3 release. Hidden inside was obfuscated code that activates two dangerous attack modes: Clipboard Hijacking: When you paste a wallet address, the malware silently swaps it with the attacker’s lookalike address. Transaction Interception: If you use a browser wallet, the code can intercept transaction calls and change the recipient’s address before you even see the confirmation screen. This makes it nearly impossible to notice unless you carefully check every single character of the address you’re sending to. Who’s at Risk from this Crypto Hack? Developers: Any project pulling dependencies without strict version pinning may have installed the infected version. This could affect CI pipelines, production builds, and apps that rely on JavaScript. Crypto Users: The malware targets major assets including $BTC, $ETH, $SOL, $TRX, $LTC, and $BCH. Both clipboard users and browser wallets are at risk. Platforms: Even centralized apps integrating npm libraries may have unknowingly included the malicious code. Which Companies were Affected? Already, SwissBorg confirmed a breach linked to a compromised partner API. Roughly 192.6K SOL (~$41.5M) was drained in the attack. While the SwissBorg app itself remains secure, its SOL Earn Program was hit, affecting <1% of users. The platform has promised recovery measures, including treasury funds and support from white-hat hackers. How to Protect Yourself Here’s what you need to do right now: For Wallet Users ✅ Always verify every transaction — check the full recipient address before signing.✅ Use a hardware wallet with clear signing enabled.✅ Avoid unnecessary browser wallet extensions.✅ If something feels off (unexpected signing requests), close the tab immediately. For Developers ⚙️ Switch CI builds from npm install to npm ci to lock dependencies.⚙️ Run npm ls error-ex to detect infected installs.⚙️ Pin safe versions (error-ex@1.3.2) and…

Crypto Funds at Risk from Massive Supply Chain Attack

Crypto Hack: What Happened?

A widely used npm package, error-ex, was tampered with in its 1.3.3 release. Hidden inside was obfuscated code that activates two dangerous attack modes:

  • Clipboard Hijacking: When you paste a wallet address, the malware silently swaps it with the attacker’s lookalike address.
  • Transaction Interception: If you use a browser wallet, the code can intercept transaction calls and change the recipient’s address before you even see the confirmation screen.

This makes it nearly impossible to notice unless you carefully check every single character of the address you’re sending to.

Who’s at Risk from this Crypto Hack?

  1. Developers: Any project pulling dependencies without strict version pinning may have installed the infected version. This could affect CI pipelines, production builds, and apps that rely on JavaScript.
  2. Crypto Users: The malware targets major assets including $BTC, $ETH, $SOL, $TRX, $LTC, and $BCH. Both clipboard users and browser wallets are at risk.
  3. Platforms: Even centralized apps integrating npm libraries may have unknowingly included the malicious code.

Which Companies were Affected?

Already, SwissBorg confirmed a breach linked to a compromised partner API. Roughly 192.6K SOL (~$41.5M) was drained in the attack. While the SwissBorg app itself remains secure, its SOL Earn Program was hit, affecting <1% of users. The platform has promised recovery measures, including treasury funds and support from white-hat hackers.

How to Protect Yourself

Here’s what you need to do right now:

For Wallet Users

✅ Always verify every transaction — check the full recipient address before signing.
✅ Use a hardware wallet with clear signing enabled.
✅ Avoid unnecessary browser wallet extensions.
✅ If something feels off (unexpected signing requests), close the tab immediately.

For Developers

⚙️ Switch CI builds from npm install to npm ci to lock dependencies.
⚙️ Run npm ls error-ex to detect infected installs.
⚙️ Pin safe versions ([email protected]) and regenerate lockfiles.
⚙️ Add dependency scanners like Snyk or Dependabot.
⚙️ Treat package-lock changes with the same scrutiny as code reviews.

Outlook

This incident highlights the fragility of supply chains in Web3 and beyond. A small package compromise can cascade into billions of downloads, hitting both developers and crypto holders worldwide. The immediate danger lies in address-swapping attacks, but the broader concern is how deep this could spread into financial infrastructure.

For now: check before you sign, pin your dependencies, and don’t take security shortcuts.

Source: https://cryptoticker.io/en/breaking-massive-supply-chain-attack-hits-crypto-funds-at-risk/

Market Opportunity
Bitcoin Cash Node Logo
Bitcoin Cash Node Price(BCH)
$593.1
$593.1$593.1
+3.81%
USD
Bitcoin Cash Node (BCH) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Microsoft Corp. $MSFT blue box area offers a buying opportunity

Microsoft Corp. $MSFT blue box area offers a buying opportunity

The post Microsoft Corp. $MSFT blue box area offers a buying opportunity appeared on BitcoinEthereumNews.com. In today’s article, we’ll examine the recent performance of Microsoft Corp. ($MSFT) through the lens of Elliott Wave Theory. We’ll review how the rally from the April 07, 2025 low unfolded as a 5-wave impulse followed by a 3-swing correction (ABC) and discuss our forecast for the next move. Let’s dive into the structure and expectations for this stock. Five wave impulse structure + ABC + WXY correction $MSFT 8H Elliott Wave chart 9.04.2025 In the 8-hour Elliott Wave count from Sep 04, 2025, we saw that $MSFT completed a 5-wave impulsive cycle at red III. As expected, this initial wave prompted a pullback. We anticipated this pullback to unfold in 3 swings and find buyers in the equal legs area between $497.02 and $471.06 This setup aligns with a typical Elliott Wave correction pattern (ABC), in which the market pauses briefly before resuming its primary trend. $MSFT 8H Elliott Wave chart 7.14.2025 The update, 10 days later, shows the stock finding support from the equal legs area as predicted allowing traders to get risk free. The stock is expected to bounce towards 525 – 532 before deciding if the bounce is a connector or the next leg higher. A break into new ATHs will confirm the latter and can see it trade higher towards 570 – 593 area. Until then, traders should get risk free and protect their capital in case of a WXY double correction. Conclusion In conclusion, our Elliott Wave analysis of Microsoft Corp. ($MSFT) suggested that it remains supported against April 07, 2025 lows and bounce from the blue box area. In the meantime, keep an eye out for any corrective pullbacks that may offer entry opportunities. By applying Elliott Wave Theory, traders can better anticipate the structure of upcoming moves and enhance risk management in volatile markets. Source: https://www.fxstreet.com/news/microsoft-corp-msft-blue-box-area-offers-a-buying-opportunity-202509171323
Share
BitcoinEthereumNews2025/09/18 03:50
WTI drifts higher above $59.50 on Kazakh supply disruptions

WTI drifts higher above $59.50 on Kazakh supply disruptions

The post WTI drifts higher above $59.50 on Kazakh supply disruptions appeared on BitcoinEthereumNews.com. West Texas Intermediate (WTI), the US crude oil benchmark
Share
BitcoinEthereumNews2026/01/21 11:24
MYX Finance price surges again as funding rate points to a crash

MYX Finance price surges again as funding rate points to a crash

MYX Finance price went parabolic again as the recent short-squeeze resumed. However, the formation of a double-top pattern and the funding rate point to an eventual crash in the coming days. MYX Finance (MYX) came in the spotlight earlier this…
Share
Crypto.news2025/09/18 02:57