NPM attack drains only $500 worth of meme coins

來源 Cryptopolitan

The recently discovered supply chain attack only affected a few wallets, drawing out around $500 in various tokens. However, the injection of malicious code into npm JavaScript packages exposed a large potential vulnerability of crypto usage. 

The recent supply chain attack, which could potentially drain crypto wallets, did not end up stealing millions. Based on the aggregated wallets used in the attack, only around $500 in assets was affected in the fist 12 hours after the vulnerability was discovered. 

As Cryptopolitan reported, initially, users were urged to stop sending crypto. However, a global permissionless system could not be stopped, and the expectation was for significant losses.  

Based on Arkham Intelligence data, the npm attacker wallets only stole around 0.22 SOL and other meme tokens for around $497. In the past day, the crypto space saw even bigger losses from the SwissBorg exchange and other protocols. However, the supply chain attack is still considered dangerous, and the small losses are due to the fact that the attacker did not get hold of any large-scale transactions. 

Supply chain npm attack resembles the Bybit hack

The supply chain attack was somewhat similar to the Bybit hack, in changing the destination wallet at the last moment. The compromised front-end code could potentially divert assets from sites that used some of the tainted JavaScript packages. 

In the case of the Bybit hack, the front end exploit was deliberate and limited, but the npm supply chain code injection has affected up to 2B weekly downloads. Early reports show the effects of the tainted npm packages were limited. 

Most of the major Web3 venues reported their code was safe and trading could continue. Most of the tokens stolen were on Ethereum, and included BRETT, DORKY, VISTA, and GONDOLA, with no ETH taken. 

The attack affected the wallets of some small-scale DEX traders and Uniswap liquidity providers, but not on a mass scale, showing the apps themselves were not compromised. The risk lay with the end client signing the transaction without sufficient manual verification. 

Is crypto still at risk from the npm attack?

Crypto wallets are generally at risk from supply chain attacks. However, the potential to steal tokens depends on the apps themselves, and on a relatively small time window to perform the exploit. 

The examples of malicious crypto-stealing code have been widely published, potentially protecting app developers. 

The attacks happened following new downloads, meaning the vulnerabilities were injected in a limited number of crypto apps. Hours after the attack, it was also clear MetaMask users were the most affected, with no targeting of the desktop wallet ecosystem.

Get up to $30,050 in trading rewards when you join Bybit today

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
搭上AI與散熱快車!漢磊成SiC概念新龍頭,暴漲背後是機會還是風險?漢磊宣布其碳化矽(SiC)第四代MOSFET製程平台(G4)實現突破。該公司總經理劉燦文表示,該技術不僅在晶片尺寸上縮小了20%,導通電阻也降低了20%,已達到「國際大廠水準」。
作者  投資-槓把子
昨日 06: 16
漢磊宣布其碳化矽(SiC)第四代MOSFET製程平台(G4)實現突破。該公司總經理劉燦文表示,該技術不僅在晶片尺寸上縮小了20%,導通電阻也降低了20%,已達到「國際大廠水準」。
placeholder
台股衝破24800點創新高!台積電站上1200元 台玻、東元一度漲停台股市場再度展現強勁動能,9日盤中一路飆升至24,874.76點的歷史新高,單日漲幅達327點。半導體巨擘台積電表現特別亮眼,成功突破1,200元重要關口,單日上漲20元,成為推升大盤的重要動力。在買盤積極湧入下,台玻、富喬雙雙攻上漲停,東元也一度觸及79.6元高點,整體市場交投熱絡。
作者  投資-槓把子
12 小時前
台股市場再度展現強勁動能,9日盤中一路飆升至24,874.76點的歷史新高,單日漲幅達327點。半導體巨擘台積電表現特別亮眼,成功突破1,200元重要關口,單日上漲20元,成為推升大盤的重要動力。在買盤積極湧入下,台玻、富喬雙雙攻上漲停,東元也一度觸及79.6元高點,整體市場交投熱絡。
placeholder
外資連5日賣超,台船(2208)股價攀升的背後,是大筆軍工訂單正在趕來台船(2208)股價近期再度上揚,從8月28日低點18.15元,一路攀升至9月8日高點27.1元,上漲幅度高達49.3%。雖然今日(9日)小幅回落,目前報價為25.65元,但受惠於優異的8月業績表現,以及潛在大單即將進帳的利多消息,台船已遭外資連續5日賣超,顯示市場對其前景的強烈期待。
作者  財富進化論
12 小時前
台船(2208)股價近期再度上揚,從8月28日低點18.15元,一路攀升至9月8日高點27.1元,上漲幅度高達49.3%。雖然今日(9日)小幅回落,目前報價為25.65元,但受惠於優異的8月業績表現,以及潛在大單即將進帳的利多消息,台船已遭外資連續5日賣超,顯示市場對其前景的強烈期待。
placeholder
黃仁勳也按讚!宜鼎(5289)強鎖漲停 法人點名這原因將續旺​投資慧眼Insights-今日宜鼎(5289)股價大漲,午盤直接亮燈鎖死在336元,離歷史高點僅一步之遙!
作者  投資指南針
8 小時前
​投資慧眼Insights-今日宜鼎(5289)股價大漲,午盤直接亮燈鎖死在336元,離歷史高點僅一步之遙!
placeholder
微軟重金押寶、華爾街瘋狂買單!一夕暴紅的「AI獨角獸」Nebius什麼來頭?投資慧眼Insights-Nebius宣佈與微軟達成接進兩百億美元的戰略協議,帶動盤後股價飆升60%!
作者  投資指南針
7 小時前
投資慧眼Insights-Nebius宣佈與微軟達成接進兩百億美元的戰略協議,帶動盤後股價飆升60%!
goTop
quote