React Vulnerability Sparks Surge in Crypto Wallet Drainer Attacks
Security Alliance (SEAL) warns of hackers exploiting a critical React vulnerability (CVE-2025-55182) to hijack cryptocurrency websites. The flaw, rated 10/10 in severity, enables remote code execution on unpatched servers running React Server Components (RSCs). React maintainers disclosed the issue on December 3, affecting versions 19.0 through 19.2.0 of react-server-dom packages.
Crypto drainers are weaponizing this vulnerability to inject malicious scripts into legitimate platforms. SEAL reports a sharp rise in attacks targeting front-end code, urging immediate review of website assets. The exploit bypasses authentication, leaving exchanges and DeFi protocols particularly exposed.
Market implications remain fluid as developers scramble for patches. Blockchain networks relying on React-based interfaces—including Ethereum, Solana, and Polygon—face elevated operational risks. The timing coincides with peak holiday trading volumes, amplifying potential attack surfaces.