Coinbase Avoids a Major Supply Chain Attack On Its Blockchain AI Toolkit

Source Beincrypto

Coinbase, the largest crypto exchange in the US, has successfully evaded a supply chain attack that could have compromised its open-source infrastructure.

On March 23, Yu Jian, founder of blockchain security firm SlowMist, flagged the incident in a post on X, referencing a report from Unit 42, the threat intelligence division of Palo Alto Networks.

How Coinbase Stopped a Major Cyber Attack

According to Unit 42, the attacker targeted ‘agentkit’, an open-source toolkit managed by Coinbase that supports blockchain-based AI agents.

The threat actor forked agentkit and onchainkit repositories on GitHub, inserting malicious code intended to exploit the continuous integration pipeline. The suspicious activity was first detected on March 14, 2025.

“The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises,” Unit 42 reported.

The attacker exploited GitHub’s “write-all” permissions, which allowed the injection of harmful code into the project’s automated workflow. This method could have enabled access to sensitive data and created a path for broader compromises.

A Malicious Commit Targeting Coinbase.A Malicious Commit Targeting Coinbase. Source: Unit42

However, Unit 42 reported that the payload collected sensitive information. It did not contain advanced malicious tools like remote code execution or reverse shell exploits.

Meanwhile, Coinbase responded quickly, collaborating with security experts to isolate the threat and apply necessary mitigations. This rapid action helped the company avoid deeper infiltration and prevented potential damage to its infrastructure.

The stakes were high considering Coinbase’s standing as the largest crypto exchange in the US and a key custodian for spot Bitcoin ETFs.

A breach of this nature could have caused major disruption across the crypto industry, especially after Bybit’s recent $1.4 billion security incident.

Despite the failed attempt, the attacker has since shifted focus to a larger campaign now drawing global attention.

In light of this, SlowMist founder advised developers using GitHub Actions—especially those working with tj-actions or reviewdog—to audit their systems and confirm that no secrets have been exposed.

“If your company uses reviewdog or tj-actions, do a thorough self-examination,” Yu Jian stated on X.

This incident highlights the growing importance of securing open-source tools as the crypto ecosystem expands. Data from DeFillama shows that the crypto industry has recorded exploits of more than $1.5 billion this year.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Ethereum (ETH) Price Closes Above $3,900 — Is a New All-Time High Possible Before 2024 Ends?Once again, the price of Ethereum (ETH) has risen above $3,900. This bounce has hinted at a further price increase for the altcoin before the end of the year.
Author  Beincrypto
Dec 17, 2024
Once again, the price of Ethereum (ETH) has risen above $3,900. This bounce has hinted at a further price increase for the altcoin before the end of the year.
placeholder
Analyst Flags XRP as Market’s ‘Best Risk/Reward’ Play as Token Tests Critical $1.60 SupportCrypto analyst Scott Melker identifies a prime risk/reward setup for XRP as it tests key support at $1.60, offering a tight stop-loss against potential upside targets near $2.00.
Author  Mitrade
Feb 03, Tue
Crypto analyst Scott Melker identifies a prime risk/reward setup for XRP as it tests key support at $1.60, offering a tight stop-loss against potential upside targets near $2.00.
placeholder
Ethereum Price Forecast: ETH faces heavy distribution as price slips below average cost basis of investorsEthereum (ETH) extended its decline on Wednesday, dropping more than 5% over the past 24 hours toward the $2,100 level, which is below the $2,310 average cost basis or realized price of investors, according to CryptoQuant's data.
Author  FXStreet
Feb 05, Thu
Ethereum (ETH) extended its decline on Wednesday, dropping more than 5% over the past 24 hours toward the $2,100 level, which is below the $2,310 average cost basis or realized price of investors, according to CryptoQuant's data.
placeholder
Bitcoin Drops to $70,000. U.S. Government Refuses to Bail Out Market, End of Bull Market or Golden Pit? The U.S. government refuses to bail out Bitcoin, and with Fed rate cuts nowhere in sight, a continued downward trend to test for a bottom is likely after a brief rebound.During the mid-da
Author  TradingKey
Feb 05, Thu
The U.S. government refuses to bail out Bitcoin, and with Fed rate cuts nowhere in sight, a continued downward trend to test for a bottom is likely after a brief rebound.During the mid-da
placeholder
Bitcoin Surrenders $65,000 as Analysts Warn of ‘Structural’ Market BreakBitcoin plunges 11% to break $65k as analysts term the crash "structural," citing a $1 trillion market wipeout and $2.09 billion in daily liquidations.
Author  Mitrade
Feb 06, Fri
Bitcoin plunges 11% to break $65k as analysts term the crash "structural," citing a $1 trillion market wipeout and $2.09 billion in daily liquidations.
goTop
quote