The post Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack appeared on BitcoinEthereumNews.com. Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say. Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said. Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X: ”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.” Source: Security Alliance “The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun told Cointelegraph in a separate comment. The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding. ETH, memecoin among small amount of crypto stolen The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far. Crypto projects that didn’t download the NPMs still at… The post Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack appeared on BitcoinEthereumNews.com. Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say. Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said. Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X: ”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.” Source: Security Alliance “The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun told Cointelegraph in a separate comment. The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding. ETH, memecoin among small amount of crypto stolen The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said. Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far. Crypto projects that didn’t download the NPMs still at…

Not Even $50 Of Crypto Stolen From Large-Scale NPM Attack

2025/09/09 20:32

Hackers have only managed to steal $50 worth of crypto from a massive supply chain hack affecting JavaScript software libraries, industry security researchers say.

Crypto intelligence platform Security Alliance shared the findings on Monday after hackers broke into the node package manager (NPM) account of a well-known software developer and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, the security firm said, identifying Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It added on X:

Source: Security Alliance

“The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun told Cointelegraph in a separate comment.

The $50 figure was, however, bumped up from five cents a few hours earlier, suggesting the potential damage may still be unfolding.

ETH, memecoin among small amount of crypto stolen

The five cents stolen were in Ether (ETH) while another $20 worth of a memecoin was compromised, Security Alliance said.

Etherscan data shows the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Crypto projects that didn’t download the NPMs still at risk

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even devs who never installed them directly could be exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

Related: Pokémon cards will soon have their ‘Polymarket moment’ — Bitwise

The attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Ledger chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.

Ledger, MetaMask among crypto apps not affected

Crypto wallet providers Ledger and MetaMask marked their platforms as safe from the NPM attack — pointing to “multiple layers of defense” to protect against such attacks.

The team behind Phantom Wallet said it doesn’t use any vulnerable versions of the affected packages, while Uniswap noted that none of its apps are at risk.

Aerodrome, Blast, Blockstream Jade and Revoke.cash were among the other crypto platforms that said they were unaffected by the supply chain attack.

Source: MetaMask

You won’t be instantly drained, crypto founder says

0xngmi, the pseudonymous founder of crypto analytics platform DefiLlama, however said only crypto projects that updated after the malware-infected NPM package was published may be at risk. Even then, users must approve the malicious transaction for it to work.

Though like Guillemet, he said it may be safer to avoid using crypto websites until developers behind those platforms clean up the bad packages.

Magazine: ‘Accidental jailbreaks’ and ChatGPT’s links to murder, suicide: AI Eye

Source: https://cointelegraph.com/news/large-scale-npm-attack-compromised-less-50-dollars?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Forget The Obituaries—Cardano Is Alive, Says Bitcoin Analyst

Forget The Obituaries—Cardano Is Alive, Says Bitcoin Analyst

Widely followed Bitcoin figure Lark Davis pushed back on suggestions that Cardano is finished, saying, “what is dead can never die.” At the same time, he pointed out that on-chain activity looks flat. Related Reading: Dogecoin Alert! Price Could Explode Over 2,800%, Analyst Says Cardano (ADA) was trading at $0.51, down 8.8% in the past 24 hours, and it holds a market cap of $18.8 billion. That is the context for a larger question now being asked across crypto circles: can community and hype move a token more than real network use? On-Chain Activity Shows Little Movement Davis admits that user activity is low and DEX volume is thin. Development updates are limited, daily revenue is weak, and stablecoins barely register on the chain. He made his point with humor too, joking that Cardano’s founder Charles Hoskinson has “a beard worth $25 billion.” But the main claim was serious: the chain’s raw on-chain metrics don’t look strong right now. Is Cardano $ADA dead? Here’s my take. ⤵️ pic.twitter.com/oGnVuQuy9N — Lark Davis (@TheCryptoLark) November 12, 2025 Community Strength And Brand Can Still Drive Prices Based on reports, Davis argued that numbers don’t tell the whole story in crypto. He compared Cardano to XRP and noted that a token can have a big market cap despite questions over intrinsic use; XRP once reached about $150 billion in market value. According to Davis, old buyers can return and push a token higher even when network use is low. That is part of why some traders treat certain assets as almost cult-like. Sentiment matters, but momentum matters more than steady on-chain growth in many cases. Technical Signals Point To A Narrow Upside If Key Levels Break TradingView analyst “AltcoinPiooners” has highlighted recent price action and a possible shift in market pressure. Reports show ADA tested support at $0.53 after hitting $0.60 on November 11 and falling the next day. Analysts See A Clear Path, But Risks Remain According to the analyst, ADA could move to $0.62 and then to $0.65 if $0.60 is cleared, a move that would equal more than a 16% gain from current levels. Reports also revealed that Cardano whales added 348 million ADA over four days while the price dipped below $0.50 recently. On the flip side, a failure at support could send ADA down toward $0.52. That risk was flagged by the same analyst. Related Reading: XRP Earns Academic Praise: University Study Calls It ‘Gold In Your Hands’ Although the debate around weak usage continues, reports have stressed that Cardano is far from dead. The project still commands a loyal base, steady interest from long-time holders, and a market cap in the billions. Featured image from Unsplash, chart from TradingView
Share
NewsBTC2025/11/15 03:00
Crypto Market: Traders Claim the Bear Market Has Begun, but One Major Signal Is Missing

Crypto Market: Traders Claim the Bear Market Has Begun, but One Major Signal Is Missing

The post Crypto Market: Traders Claim the Bear Market Has Begun, but One Major Signal Is Missing appeared on BitcoinEthereumNews.com. Key Insights Many crypto market traders believe the bear market is already here, but several signals do not match a real cycle top. The Pi Cycle Top indicator, which has called the last three tops, has not triggered yet. Past bear markets only began after a confirmed top, not before it, which suggests this cycle may still have room left. The crypto market has been falling for weeks. Many traders now believe the bear market has already begun. The total market cap was near $3.94 trillion on 6 October. It corrected to $3.59 trillion on 11 November. It then dropped again to almost $3.20 trillion this week. These are big moves, so fear is rising fast. But when we place all signals side by side, the picture is not complete. Several charts show weakness. But the main top signal for Bitcoin has not appeared yet. Crypto Market: Traders Think Bear Market Already Started Many shared charts point to some tension for the crypto prices. One chart shows Bicoin USD heading lower than the 50-week moving average. A moving average shows the average price over time, and traders watch it to track the price and market trend. Bitcoin 50W MA Signal | Source: X Older charts compare the 2025 to 2015–2018 and 2018–2021 (4-year moves). In those charts, the peak looks like it formed in late October. This made the correction look like the start of a new downtrend. Do note that it was in October when the Bitcoin price hit a new peak of $126,000. Crypto Market Older Cycles | Source: X Some on-chain charts show long-term holders moving coins. The rise in CDD suggests older coins are transferring, which can look like early selling. Crypto Market CDD Looks Bearish | Source: X ETFs also added pressure. Bitcoin ETFs saw…
Share
BitcoinEthereumNews2025/11/15 03:38