BTCC / BTCC Square / Global Cryptocurrency /
Crypto Users Warned of Massive JavaScript Exploit Threatening Wallets and Apps

Crypto Users Warned of Massive JavaScript Exploit Threatening Wallets and Apps

Published:
2025-09-08 19:58:02
23
2
BTCCSquare news:

A critical supply-chain attack targeting JavaScript's NPM ecosystem has put cryptocurrency users at severe risk. Ledger CTO Charles Guillemet revealed that compromised code packages—downloaded over 1 billion times—contain malicious payloads capable of swapping crypto addresses mid-transaction to steal funds.

The exploit impacts potentially all blockchain networks, with Guillemet warning the entire JavaScript ecosystem may be vulnerable. Blockchain security firm Blockaid estimates two dozen popular packages are affected. "I WOULD strongly recommend not signing any crypto transactions right now," cautioned developer Cygaar, noting multiple crypto websites could be compromised.

The breach originated from a high-profile developer's hijacked NPM account, demonstrating how single points of failure can threaten decentralized finance infrastructure. Security teams are scrambling to contain what may become one of the most far-reaching crypto exploits in history.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users