

De-fi
Massive Software Supply-Chain Hack Targeting Crypto Ends with Pennies Stolen – Crypto News
One web developer’s compromised npm account triggered a large-scale supply chain attack, but the hacker only got a few cents in crypto, analysts say.
An unknown hacker pulled off what may be the largest software supply-chain attack ever, but still made less than the price of many memecoins.
On Monday, Sept. 8, a hacker broke into the account of a well-known JavaScript developer known as “qix” and pushed malicious updates to dozens of widely used software tools for building websites and apps, which together are downloaded more than two billion times each week.
After gaining access, the hacker added malicious code to all of the developer’s packages, which wasn’t a virus in the traditional sense but was still designed to steal cryptocurrency from users’ crypto wallets in browsers.
The attack immediately caused chaos as developer updates are usually automatically trusted, so when new versions come in, many projects and apps accept them without checking, letting the hacker’s code spread fast.
Snir Levi, founder and CEO of compliance and threat management platform Nominis, told The Defiant that the modern software supply chain is “incredibly interconnected,” as a single compromised npm account can cascade across thousands of projects and businesses in minutes, because code reuse is the “backbone of the entire ecosystem.” Npm is a registry for JavaScript software packages.
“The stakes aren’t just technical – a malicious package in a critical dependency can impact millions of users, move billions of dollars, and undermine trust in the integrity of the industry. This incident highlights that security isn’t just about protecting infrastructure; it’s about protecting every link in a vast, invisible web of trust,” Levi explained.
The malicious code, mainly targeting Ethereum and Solana transactions, was created to swap destination addresses to the hacker’s wallet, the Security Alliance wrote in a post-attack blog post on Monday.
The cybersecurity experts say that the code also tried to rewrite crypto addresses inside web traffic with look-alike ones.
‘Generational Fumble’
While on paper the attack was catastrophic, in terms of actual losses, the Security Alliance says that the hacker made only about $0.05 worth of ETH and $20 in a memecoin.
“Despite the magnitude of the breach, the attacker appears to have only ‘stolen’ around 5 cents of ETH and 20 USD of a memecoin with a whopping 588 USD of trading volume over the past 24 hours,” the Security Alliance said.
Commenting on the attack in an X post, samczsun, a pseudonymous white hat hacker and the founder of the Security Alliance, described the incident as a “generational fumble, the likes of which we will probably never see again.”
Harry Donnelly, CEO of digital asset recovery company Circuit, suggested in commentary for The Defiant that this attack is far from the last one as there are “many dependencies and vulnerabilities in the crypto supply chain.”
“This attack is an example of how something as small as an open-source package installed by one developer can create an unintended attack vector. Having measures in place to respond to malicious activity, even if the payload is replaced, is critically important to prevent funds from being stolen,” Donnelly added.
-
Blockchain1 week ago
Etherealize Raises $40M to Market Ethereum to Finance Firms – Crypto News
-
others7 days ago
XAG/USD bounces at $40.50, approaching $41.00 – Crypto News
-
Cryptocurrency7 days ago
Reverse-takeover DATs are a grab bag of risks for investors – Crypto News
-
Cryptocurrency7 days ago
Ripple (XRP) Slips 5% Weekly But Analysts See Potential for a New ATH – Crypto News
-
others1 week ago
CFTC Gives Crypto Prediction Platform Polymarket Greenlight To Launch In the U.S. – Crypto News
-
Cryptocurrency1 week ago
Historic Bitcoin-S&P decoupling fuels altseason hopes – All the details! – Crypto News
-
Cryptocurrency6 days ago
Regulatory Certainty for Crypto Front and Center on SEC’s Agenda – Crypto News
-
Blockchain1 week ago
Ukraine’s Parliament Supports Crypto Tax Bill at First Reading – Crypto News
-
Business1 week ago
1inch Taps Ondo Finance to Unlock Access to Tokenized RWAs – Crypto News
-
Cryptocurrency1 week ago
XRP Army Played Key Role in Ripple SEC Lawsuit, John Deaton Says – Crypto News
-
Technology1 week ago
India ranks among top 5 contributors to open source projects: CNCF – Crypto News
-
Business1 week ago
Wintermute Addresses US SEC on Tokenized Securities as Coinbase, Kraken Seek License – Crypto News
-
Business1 week ago
Wintermute Addresses US SEC on Tokenized Securities as Coinbase, Kraken Seek License – Crypto News
-
others1 week ago
Dow Jones falls flat as tech stocks rise – Crypto News
-
Blockchain1 week ago
Cardano Founder Says Chainlink Quoted Them An ‘Absurd Price’, Here’s Why – Crypto News
-
Business1 week ago
AlphaTON Capital Launches $100M TON Treasury Strategy, Rebrands as ATON on Nasdaq – Crypto News
-
others7 days ago
What’s Fueling Today’s Crypto Market Crash? – Crypto News
-
Cryptocurrency1 week ago
Is SKY’s 10% surge a bull trap in disguise? Marking major levels – Crypto News
-
Cryptocurrency1 week ago
Sky Protocol buyback program starts paying off as SKY token jumps 12% – Crypto News
-
others6 days ago
Duluth Holdings (DLTH) tops Q2 earnings and revenue estimates – Crypto News
-
Blockchain5 days ago
Ethereum Outflows Drive Binance Supply Ratio Under 0.037, Signaling Bullish Setup – Crypto News
-
De-fi7 days ago
Layer 2 Starknet Recovers After Four-Hour Outage – Crypto News
-
De-fi1 week ago
Trump-Linked WLFI Token Tanks 18% in First 24 Hours of Trading – Crypto News
-
De-fi1 week ago
Kraken, Backed Expand Tokenized US Stocks to Ethereum via xStocks – Crypto News
-
Blockchain5 days ago
SUI Price To $7? Analyst Predicts Altcoin’s Path To New ATH – Crypto News
-
Cryptocurrency1 week ago
Crypto update: Why Bitcoin is stalling while Ethereum eyes a breakout – Crypto News
-
Blockchain5 days ago
Bitcoin Unlikely To Reach Price Peak In Q4 2025: Analyst – Crypto News
-
Blockchain5 days ago
Senate Crypto Bill Clarifies Tokenized Stocks Remain Securities – Crypto News
-
Cryptocurrency1 week ago
Cardano Developer IOG Dispels ‘FUD’ with Major Audit – Crypto News
-
others6 days ago
The Gary Gensler Files: Missing Texts Correlate to FTX Collapse Timing, Says Expert – Crypto News
-
Blockchain5 days ago
Bitcoin Unlikely To Reach Price Peak In Q4 2025: Analyst – Crypto News
-
Blockchain5 days ago
Bitcoin Unlikely To Reach Price Peak In Q4 2025: Analyst – Crypto News
-
Blockchain5 days ago
SUI Breakout Structure Builds – Can The Bulls Push Past $3.50? – Crypto News
-
Blockchain4 days ago
Bitcoin STH-SOPR Metric Reclaims Critical Level — More Pain For Short-Term Holders? – Crypto News
-
Technology1 week ago
Hyperliquid Records Best Month Ever in Revenue Following HYPE ATH Surge – Crypto News
-
Cryptocurrency1 week ago
Major Shiba Inu Market Maker Sends Billions of SHIB to Coinbase: What’s Happening? – Crypto News
-
Cryptocurrency1 week ago
Nasdaq-Listed BNC Expands BNB Treasury, Targets 1% Token Supply – Crypto News
-
Cryptocurrency1 week ago
Ethena price forecast amid a 94 million ENA token unlock – Crypto News
-
Technology1 week ago
Googles AI rivals get a boost from data-sharing order, but tech giant far from routed – Crypto News
-
others6 days ago
DOJ Launches Criminal Probe Into Fed’s Lisa Cook Ahead of FOMC Meeting – Crypto News
-
Metaverse1 week ago
Healthtech startups bet on AI to build electronic health records but adoption in India remains slow – Crypto News
-
Business1 week ago
XRP Price Forecast as $30M Treasury Push Fuels Growth — Is a 66% Rally Ahead? – Crypto News
-
Cryptocurrency1 week ago
Cardano Developer IOG Dispels ‘FUD’ with Major Audit – Crypto News
-
Business1 week ago
Wintermute Addresses US SEC on Tokenized Securities as Coinbase, Kraken Seek License – Crypto News
-
Technology7 days ago
Ripple expands RLUSD stablecoin into Africa to power cross-border payments – Crypto News
-
Business7 days ago
BlackRock Dumps $151M ETH, Doubles Down on Bitcoin With $290M Buy – Crypto News
-
Blockchain5 days ago
Senate Crypto Bill Clarifies Tokenized Stocks Remain Securities – Crypto News
-
Blockchain4 days ago
Bitcoin Mining Difficulty Reaches New All-Time High – Crypto News
-
Blockchain4 days ago
Ethereum Exchange Balance Just Went Negative For The First Time Ever, Why This Is Very Bullish For Price – Crypto News
-
Cryptocurrency1 week ago
4 Trends Show How Privacy Is Moving From Niche To Necessity In DeFi Trading – Crypto News