De-fi
Massive Software Supply-Chain Hack Targeting Crypto Ends with Pennies Stolen – Crypto News
One web developer’s compromised npm account triggered a large-scale supply chain attack, but the hacker only got a few cents in crypto, analysts say.
An unknown hacker pulled off what may be the largest software supply-chain attack ever, but still made less than the price of many memecoins.
On Monday, Sept. 8, a hacker broke into the account of a well-known JavaScript developer known as “qix” and pushed malicious updates to dozens of widely used software tools for building websites and apps, which together are downloaded more than two billion times each week.
After gaining access, the hacker added malicious code to all of the developer’s packages, which wasn’t a virus in the traditional sense but was still designed to steal cryptocurrency from users’ crypto wallets in browsers.
The attack immediately caused chaos as developer updates are usually automatically trusted, so when new versions come in, many projects and apps accept them without checking, letting the hacker’s code spread fast.
Snir Levi, founder and CEO of compliance and threat management platform Nominis, told The Defiant that the modern software supply chain is “incredibly interconnected,” as a single compromised npm account can cascade across thousands of projects and businesses in minutes, because code reuse is the “backbone of the entire ecosystem.” Npm is a registry for JavaScript software packages.
“The stakes aren’t just technical – a malicious package in a critical dependency can impact millions of users, move billions of dollars, and undermine trust in the integrity of the industry. This incident highlights that security isn’t just about protecting infrastructure; it’s about protecting every link in a vast, invisible web of trust,” Levi explained.
The malicious code, mainly targeting Ethereum and Solana transactions, was created to swap destination addresses to the hacker’s wallet, the Security Alliance wrote in a post-attack blog post on Monday.
The cybersecurity experts say that the code also tried to rewrite crypto addresses inside web traffic with look-alike ones.
‘Generational Fumble’
While on paper the attack was catastrophic, in terms of actual losses, the Security Alliance says that the hacker made only about $0.05 worth of ETH and $20 in a memecoin.
“Despite the magnitude of the breach, the attacker appears to have only ‘stolen’ around 5 cents of ETH and 20 USD of a memecoin with a whopping 588 USD of trading volume over the past 24 hours,” the Security Alliance said.
Commenting on the attack in an X post, samczsun, a pseudonymous white hat hacker and the founder of the Security Alliance, described the incident as a “generational fumble, the likes of which we will probably never see again.”
Harry Donnelly, CEO of digital asset recovery company Circuit, suggested in commentary for The Defiant that this attack is far from the last one as there are “many dependencies and vulnerabilities in the crypto supply chain.”
“This attack is an example of how something as small as an open-source package installed by one developer can create an unintended attack vector. Having measures in place to respond to malicious activity, even if the payload is replaced, is critically important to prevent funds from being stolen,” Donnelly added.
-
Blockchain1 week agoThe Quantum Clock Is Ticking on Blockchain Security – Crypto News
-
Technology1 week agoHow Americans are using AI at work, according to a new Gallup poll – Crypto News
-
Technology1 week agoHow Americans are using AI at work, according to a new Gallup poll – Crypto News
-
Metaverse4 days agoContext engineering and the Future of AI-powered business – Crypto News
-
Blockchain1 week agoTether Launches Dollar-Backed Stablecoin USAT – Crypto News
-
Metaverse4 days agoStop panicking about AI. Start preparing – Crypto News
-
Cryptocurrency1 week agoRiver Crypto Token Up 1,900% in the Last Month—What’s the Deal? – Crypto News
-
Metaverse4 days agoContext engineering and the Future of AI-powered business – Crypto News
-
Metaverse4 days agoContext engineering and the Future of AI-powered business – Crypto News
-
Blockchain1 week agoTrump-Backed WLFI Snaps Up 2,868 ETH, Sells $8M WBTC – Crypto News
-
Blockchain1 week agoTrump-Backed WLFI Snaps Up 2,868 ETH, Sells $8M WBTC – Crypto News
-
Blockchain1 week agoUS Storm Smashes Bitcoin Mining Power, Sending Hash Rates Tumbling – Crypto News
-
Metaverse1 week agoIs AI eating up jobs in UK? New report paints bleak picture – Crypto News
-
Cryptocurrency1 week agoTrump family-backed American Bitcoin achieves 116% BTC yield – Crypto News
-
Cryptocurrency1 week agoRiver price defies market downturn, explodes 40% to new ATH – Crypto News
-
Cryptocurrency1 week agoMakinaFi hit by $4.1M Ethereum hack as MEV tactics suspected – Crypto News
-
Technology1 week agoHow Americans are using AI at work, according to a new Gallup poll – Crypto News
-
others1 week agoPBOC sets USD/CNY reference rate at 6.9843 vs. 6.9929 previous – Crypto News
-
Blockchain1 week agoKalshi Expands Political Footprint with DC Office, Democratic Hire – Crypto News
-
Technology1 week agoElon Musk says ‘WhatsApp is not secure’ amid Meta privacy lawsuit; Sridhar Vembu cites ‘conflict of interest’ – Crypto News
-
Business1 week ago
Bitcoin and XRP Price At Risk As US Govt. Shutdown Odds Reach 73% – Crypto News
-
Business1 week ago
Bitcoin and XRP Price At Risk As US Govt. Shutdown Odds Reach 73% – Crypto News
-
Business1 week ago
Bitcoin Sentiment Weakens BTC ETFs Lose $103M- Is A Crash Imminent? – Crypto News
-
Business1 week ago
Japan Set to Launch First Crypto ETFs as Early as 2028: Nikkei – Crypto News
-
Cryptocurrency1 week agoRYO Digital Announces 2025 Year-End Milestones Across Its Ecosystem – Crypto News
-
Cryptocurrency1 week agoRiver Crypto Token Up 1,900% in the Last Month—What’s the Deal? – Crypto News
-
Business1 week ago
Experts Advise Caution As Crypto Market Heads Into A Bearish Week Ahead – Crypto News
-
Business1 week ago
Experts Advise Caution As Crypto Market Heads Into A Bearish Week Ahead – Crypto News
-
Blockchain1 week ago‘Most Reliable’ Bitcoin Price Signal Hints at a 2026 Bull Run – Crypto News
-
Technology1 week ago
Bitcoin And XRP Price Prediction Ahead of FOMC Meeting Tomorrow, Jan 28 – Crypto News
-
Technology1 week ago
Bitcoin And XRP Price Prediction Ahead of FOMC Meeting Tomorrow, Jan 28 – Crypto News
-
Technology1 week ago
Bitcoin And XRP Price Prediction Ahead of FOMC Meeting Tomorrow, Jan 28 – Crypto News
-
Business1 week ago
Bitcoin Faces Renewed Volatility as Investors Explore Options Like Everlight – Crypto News
-
others1 week agoUS Dollar hits 2022 lows as ‘Sell America’ trade intensifies ahead of Fed’s decision – Crypto News
-
others1 week ago
Jerome Powell Speech Tomorrow: What to Expect From Fed Meeting for Crypto Market? – Crypto News
-
others1 week agoMichael Saylor’s Strategy Buys Another $264,100,000 in Bitcoin (BTC) Amid Crypto Market Downturn – Crypto News
-
Technology2 days ago
Fed Rate Cut Uncertainty Mounts as BLS Delays Jobs Report Amid Shutdown – Crypto News
-
Business1 week ago
Bitcoin and XRP Price At Risk As US Govt. Shutdown Odds Reach 73% – Crypto News
-
others1 week ago
U.S. Shutdown Odds Hit 78% as CLARITY Act Faces Fresh Uncertainty – Crypto News
-
others1 week ago478,188 Americans Warned After Hackers Strike Government-Related Firm Handling Sensitive Personal Data – Crypto News
-
Technology1 week ago
Crypto Events to Watch This Week: Is the Market Entering a New Recovery Phase? – Crypto News
-
Blockchain1 week agoCZ Won’t Return to Binance, Bullish on Bitcoin Supercycle – Crypto News
-
Blockchain1 week agoSolana (SOL) Slips Further As Bears Target Deeper Support Zones – Crypto News
-
Technology1 week agoIs TikTok still down in the United States? Check current status – Crypto News
-
Cryptocurrency1 week agoThe productivity bull case for almost everything – Crypto News
-
Business1 week ago
Experts Advise Caution As Crypto Market Heads Into A Bearish Week Ahead – Crypto News
-
Technology1 week ago
Bitcoin And XRP Price Prediction Ahead of FOMC Meeting Tomorrow, Jan 28 – Crypto News
-
Cryptocurrency1 week agoHyperliquid explained: The $3 trillion DEX that’s shaking up crypto trading – Crypto News
-
Cryptocurrency1 week ago
Pi Network Price Prediction as 134M Token Unlock in Jan 2026 Could Mark a New All-Time Low – Crypto News
-
Technology1 week ago
Pi Network Price Prediction as 134M Token Unlock in Jan 2026 Could Mark a New All-Time Low – Crypto News
