Charles Guillemet, Chief Technology Officer at Ledger, warned on Monday of a large-scale supply chain attack targeting crypto software wallets after the Node Package Manager (NPM) account of open-source developer qix was compromised.Charles Guillemet, Chief Technology Officer at Ledger, warned on Monday of a large-scale supply chain attack targeting crypto software wallets after the Node Package Manager (NPM) account of open-source developer qix was compromised.

Crypto software wallets at risk following supply chain attack

2025/09/09 08:52
3 min read
  • Ledger CTO Charles Guillemet warned of a large-scale supply chain attack that could affect software crypto wallets.
  • The warning follows reports of a reputable developer's NPM account being compromised.
  • Guillemet cautioned against performing on-chain transactions.

Charles Guillemet, Chief Technology Officer at Ledger, warned on Monday of a large-scale supply chain attack targeting crypto software wallets after the Node Package Manager (NPM) account of open-source developer qix was compromised.

Software wallets could face attacks from NPM breach

Crypto software wallets could be vulnerable to malicious attacks when performing transactions, said Guillemet in an X post on Monday.

Guillemet noted that a major supply chain attack has been underway after reputable developer qix's NPM account was compromised.

A supply chain attack targets a third-party vendor that provides services or software essential to the supply chain.

The hacked NPM was reportedly used to distribute malware designed to scan and exploit crypto wallets. Once crypto is detected, the malware alters the code responsible for signing transactions and redirects funds to addresses controlled by its creators.

"The malicious payload works by silently swapping crypto addresses on the fly to steal funds," wrote Guillemet.

NPM serves as a central registry and library for JavaScript software packages, offering command-line tools that allow developers to install and manage packages. NPM is largely used on open-source platforms and is a core part of the JavaScript ecosystem, widely relied upon for sharing and distributing code.

Guillemet added that the packages involved had been downloaded more than a billion times.

He noted that the malware poses a greater risk to software wallet users than to those with hardware wallets, urging the former to avoid making on-chain transactions.

"If you use a hardware wallet, pay attention to every transaction before signing and you're safe. If you don't use a hardware wallet, refrain from making any on-chain transactions for now," Guillemet added.

The development sparked concerns among crypto developers about the potential impact of the attacks on crypto wallets.

DefiLlama developer and pseudonymous figure Oxngmi stated on X that the supply-chain attack can only affect websites that "pushed an update since the hacked NPM package was published."

https://x.com/0xngmi/status/1965125988016087050

He reiterated Guillemet's view, stating that it is "safer to avoid using crypto websites till this blows over and they clean up the bad packages."

However, several top crypto platforms, including MetaMask wallet, Uniswap, Aave and Jupiter have stated that their systems are unaffected by the developments.

Meanwhile, Switzerland-based crypto exchange SwissBorg suffered an attack in which hackers stole 193,000 SOL, worth about $41.5 million at the time. The exchange stated that the attack involved the compromise of a partner API in its SOL Earn Program, affecting less than 1% of users.


Market Opportunity
NODE Logo
NODE Price(NODE)
$0.01425
$0.01425$0.01425
-0.14%
USD
NODE (NODE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

The post American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight appeared on BitcoinEthereumNews.com. Key Takeaways: American Bitcoin (ABTC) surged nearly 85% on its Nasdaq debut, briefly reaching a $5B valuation. The Trump family, alongside Hut 8 Mining, controls 98% of the newly merged crypto-mining entity. Eric Trump called Bitcoin “modern-day gold,” predicting it could reach $1 million per coin. American Bitcoin, a fast-rising crypto mining firm with strong political and institutional backing, has officially entered Wall Street. After merging with Gryphon Digital Mining, the company made its Nasdaq debut under the ticker ABTC, instantly drawing global attention to both its stock performance and its bold vision for Bitcoin’s future. Read More: Trump-Backed Crypto Firm Eyes Asia for Bold Bitcoin Expansion Nasdaq Debut: An Explosive First Day ABTC’s first day of trading proved as dramatic as expected. Shares surged almost 85% at the open, touching a peak of $14 before settling at lower levels by the close. That initial spike valued the company around $5 billion, positioning it as one of 2025’s most-watched listings. At the last session, ABTC has been trading at $7.28 per share, which is a small positive 2.97% per day. Although the price has decelerated since opening highs, analysts note that the company has been off to a strong start and early investor activity is a hard-to-find feat in a newly-launched crypto mining business. According to market watchers, the listing comes at a time of new momentum in the digital asset markets. With Bitcoin trading above $110,000 this quarter, American Bitcoin’s entry comes at a time when both institutional investors and retail traders are showing heightened interest in exposure to Bitcoin-linked equities. Ownership Structure: Trump Family and Hut 8 at the Helm Its management and ownership set up has increased the visibility of the company. The Trump family and the Canadian mining giant Hut 8 Mining jointly own 98 percent…
Share
BitcoinEthereumNews2025/09/18 01:33
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41
Strategic Investment Plays Amid Rising US-Iran Tensions

Strategic Investment Plays Amid Rising US-Iran Tensions

US-Iran tensions drive market rotation into energy and defense sectors. Analysis of BP, Chord Energy, Lockheed Martin, Northrop Grumman, and Eos Energy stocks.
Share
Blockonomi2026/03/02 00:41