NPM attack drains only $500 worth of meme coins

來源 Cryptopolitan

The recently discovered supply chain attack only affected a few wallets, drawing out around $500 in various tokens. However, the injection of malicious code into npm JavaScript packages exposed a large potential vulnerability of crypto usage. 

The recent supply chain attack, which could potentially drain crypto wallets, did not end up stealing millions. Based on the aggregated wallets used in the attack, only around $500 in assets was affected in the fist 12 hours after the vulnerability was discovered. 

As Cryptopolitan reported, initially, users were urged to stop sending crypto. However, a global permissionless system could not be stopped, and the expectation was for significant losses.  

Based on Arkham Intelligence data, the npm attacker wallets only stole around 0.22 SOL and other meme tokens for around $497. In the past day, the crypto space saw even bigger losses from the SwissBorg exchange and other protocols. However, the supply chain attack is still considered dangerous, and the small losses are due to the fact that the attacker did not get hold of any large-scale transactions. 

Supply chain npm attack resembles the Bybit hack

The supply chain attack was somewhat similar to the Bybit hack, in changing the destination wallet at the last moment. The compromised front-end code could potentially divert assets from sites that used some of the tainted JavaScript packages. 

In the case of the Bybit hack, the front end exploit was deliberate and limited, but the npm supply chain code injection has affected up to 2B weekly downloads. Early reports show the effects of the tainted npm packages were limited. 

Most of the major Web3 venues reported their code was safe and trading could continue. Most of the tokens stolen were on Ethereum, and included BRETT, DORKY, VISTA, and GONDOLA, with no ETH taken. 

The attack affected the wallets of some small-scale DEX traders and Uniswap liquidity providers, but not on a mass scale, showing the apps themselves were not compromised. The risk lay with the end client signing the transaction without sufficient manual verification. 

Is crypto still at risk from the npm attack?

Crypto wallets are generally at risk from supply chain attacks. However, the potential to steal tokens depends on the apps themselves, and on a relatively small time window to perform the exploit. 

The examples of malicious crypto-stealing code have been widely published, potentially protecting app developers. 

The attacks happened following new downloads, meaning the vulnerabilities were injected in a limited number of crypto apps. Hours after the attack, it was also clear MetaMask users were the most affected, with no targeting of the desktop wallet ecosystem.

Get up to $30,050 in trading rewards when you join Bybit today

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
比特幣收復7萬美元!木頭姐聲稱接近潛在底部,這次會不一樣嗎?比特幣價格反彈至7萬美元上方,木頭姐再次喊話「可能見底」,但事實未必如此。週一(2月9日),比特幣 (BTC) 價格反彈停滯不前,維持在7萬美元附近震蕩,當前價格為70,487美元。三天前,比特幣價格跌至6萬美元,當天出現強勢的V型反彈。比特幣價格圖表,來源:TradingView比特幣價格通常在不同交易所略微有差異,而這次在韓國交易所Bithumb出現5000美元的差距
作者  TradingKey
12 小時前
比特幣價格反彈至7萬美元上方,木頭姐再次喊話「可能見底」,但事實未必如此。週一(2月9日),比特幣 (BTC) 價格反彈停滯不前,維持在7萬美元附近震蕩,當前價格為70,487美元。三天前,比特幣價格跌至6萬美元,當天出現強勢的V型反彈。比特幣價格圖表,來源:TradingView比特幣價格通常在不同交易所略微有差異,而這次在韓國交易所Bithumb出現5000美元的差距
placeholder
日本大選後日幣巨震,非農數據能否助力美元?【外匯週報】高市早苗大勝日本選舉!日幣匯率巨震。非農和CPI來襲!歐元/美元能否反彈?
作者  Alison Ho
12 小時前
高市早苗大勝日本選舉!日幣匯率巨震。非農和CPI來襲!歐元/美元能否反彈?
placeholder
黃金5000心理關口難定方向,「中繼」或僅剛剛開始黃金收復5000美元心理關口,新一輪升勢或仍需耐心等待;黃金「中繼」或僅剛剛開始,聚焦非農數據;黃金技術分析:高位整理格局,關注4600-5100區間
作者  Insights
12 小時前
黃金收復5000美元心理關口,新一輪升勢或仍需耐心等待;黃金「中繼」或僅剛剛開始,聚焦非農數據;黃金技術分析:高位整理格局,關注4600-5100區間
placeholder
【今日要聞】高市早苗大勝日本選舉,黃金價格重回5000美元高市早苗大勝日本選舉,日幣匯率先跌後漲;黃金價格重回5000美元,白銀漲超4%;美伊談判繼續,油價下跌>>
作者  Alison Ho
12 小時前
高市早苗大勝日本選舉,日幣匯率先跌後漲;黃金價格重回5000美元,白銀漲超4%;美伊談判繼續,油價下跌>>
placeholder
美1月非農和CPI重磅來襲!年度就業或大幅下修?美元、黃金迎巨震!若非農數據大幅不如預期,將打擊美元、利好黃金價格上漲。若出現「就業弱+通膨強」的組合,市場波動或加劇。
作者  Alison Ho
15 小時前
若非農數據大幅不如預期,將打擊美元、利好黃金價格上漲。若出現「就業弱+通膨強」的組合,市場波動或加劇。
goTop
quote