• bitcoinBitcoin (BTC) $ 81,232.00
  • ethereumEthereum (ETH) $ 2,530.69
  • tetherTether (USDT) $ 0.998520
  • bnbBNB (BNB) $ 810.81
  • xrpXRP (XRP) $ 1.64
  • usd-coinUSDC (USDC) $ 0.999693
  • solanaSolana (SOL) $ 108.75
  • jusdJUSD (JUSD) $ 0.999053
  • tronTRON (TRX) $ 0.287620
  • staked-etherLido Staked Ether (STETH) $ 2,526.59
  • dogecoinDogecoin (DOGE) $ 0.106953
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • cardanoCardano (ADA) $ 0.298701
  • wrapped-stethWrapped stETH (WSTETH) $ 3,095.92
  • whitebitWhiteBIT Coin (WBT) $ 50.58
  • bitcoin-cashBitcoin Cash (BCH) $ 520.03
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 80,800.00
  • usdsUSDS (USDS) $ 0.999790
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,755.69
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999062
  • moneroMonero (XMR) $ 466.75
  • leo-tokenLEO Token (LEO) $ 9.12
  • wrapped-eethWrapped eETH (WEETH) $ 2,745.97
  • chainlinkChainlink (LINK) $ 10.06
  • canton-networkCanton (CC) $ 0.187192
  • hyperliquidHyperliquid (HYPE) $ 29.13
  • ethena-usdeEthena USDe (USDE) $ 0.997457
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 81,281.00
  • stellarStellar (XLM) $ 0.179245
  • wethWETH (WETH) $ 2,526.34
  • usd1-wlfiUSD1 (USD1) $ 0.998577
  • zcashZcash (ZEC) $ 306.94
  • litecoinLitecoin (LTC) $ 60.28
  • suiSui (SUI) $ 1.17
  • susdssUSDS (SUSDS) $ 1.09
  • usdt0USDT0 (USDT0) $ 0.996785
  • avalanche-2Avalanche (AVAX) $ 10.12
  • daiDai (DAI) $ 1.00
  • shiba-inuShiba Inu (SHIB) $ 0.000007
  • hedera-hashgraphHedera (HBAR) $ 0.090907
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.141654
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • tether-goldTether Gold (XAUT) $ 4,879.69
  • the-open-networkToncoin (TON) $ 1.35
  • crypto-com-chainCronos (CRO) $ 0.079834
  • rainRain (RAIN) $ 0.008764
  • polkadotPolkadot (DOT) $ 1.57
  • uniswapUniswap (UNI) $ 3.98
  • mantleMantle (MNT) $ 0.732083
  • bitget-tokenBitget Token (BGB) $ 3.31
  • memecoreMemeCore (M) $ 1.28
  • falcon-financeFalcon USD (USDF) $ 0.992965
  • pax-goldPAX Gold (PAXG) $ 4,905.79
  • aaveAave (AAVE) $ 132.59
  • okbOKB (OKB) $ 93.11
  • bittensorBittensor (TAO) $ 197.46
  • pepePepe (PEPE) $ 0.000004
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.23
  • htx-daoHTX DAO (HTX) $ 0.000002
  • global-dollarGlobal Dollar (USDG) $ 0.999538
  • nearNEAR Protocol (NEAR) $ 1.23
  • jito-staked-solJito Staked SOL (JITOSOL) $ 137.05
  • ethereum-classicEthereum Classic (ETC) $ 9.93
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,699.29
  • pump-funPump.fun (PUMP) $ 0.002611
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,527.54
  • internet-computerInternet Computer (ICP) $ 2.78
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • skySky (SKY) $ 0.062216
  • pi-networkPi Network (PI) $ 0.162512
  • ondo-financeOndo (ONDO) $ 0.287297
  • hash-2Provenance Blockchain (HASH) $ 0.024310
  • ripple-usdRipple USD (RLUSD) $ 0.999752
  • aster-2Aster (ASTER) $ 0.547441
  • bfusdBFUSD (BFUSD) $ 0.998105
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999855
  • kucoin-sharesKuCoin (KCS) $ 9.57
  • wbnbWrapped BNB (WBNB) $ 809.95
  • binance-staked-solBinance Staked SOL (BNSOL) $ 119.39
  • worldcoin-wldWorldcoin (WLD) $ 0.419435
  • gatechain-tokenGate (GT) $ 8.47
  • ethenaEthena (ENA) $ 0.139798
  • usddUSDD (USDD) $ 0.998862
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.103760
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,921.84
  • aptosAptos (APT) $ 1.30
  • official-trumpOfficial Trump (TRUMP) $ 4.34
  • quant-networkQuant (QNT) $ 66.80
  • cosmosCosmos Hub (ATOM) $ 1.98
  • myx-financeMYX Finance (MYX) $ 5.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 81,229.00
  • algorandAlgorand (ALGO) $ 0.103363
  • kaspaKaspa (KAS) $ 0.033726
  • ignition-fbtcFunction FBTC (FBTC) $ 81,055.00
  • nexoNEXO (NEXO) $ 0.862879
  • usdtbUSDtb (USDTB) $ 0.996583
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.97
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999694
  • arbitrumArbitrum (ARB) $ 0.141527
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • render-tokenRender (RENDER) $ 1.57
  • filecoinFilecoin (FIL) $ 1.08
  • midnight-3Midnight (NIGHT) $ 0.048459
  • flare-networksFlare (FLR) $ 0.009480
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.999799
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,754.82
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • vechainVeChain (VET) $ 0.008470
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • ousgOUSG (OUSG) $ 114.15
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,671.56
  • xdce-crowd-saleXDC Network (XDC) $ 0.035441
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 29.49
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 81,161.00
  • bonkBonk (BONK) $ 0.000007
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 80,732.00
  • morphoMorpho (MORPHO) $ 1.16
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999706
  • usdaiUSDai (USDAI) $ 0.999589
  • cocaCOCA (COCA) $ 1.28
  • clbtcclBTC (CLBTC) $ 79,252.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.186469
  • riverRiver (RIVER) $ 30.71
  • beldexBeldex (BDX) $ 0.078344
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,527.54
  • sei-networkSei (SEI) $ 0.089338
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,685.92
  • usual-usdUsual USD (USD0) $ 0.997163
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,707.82
  • dashDash (DASH) $ 45.20
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • story-2Story (IP) $ 1.61
  • wrapped-flareWrapped Flare (WFLR) $ 0.009467
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 126.65
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.64
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,523.34
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.54
  • ghoGHO (GHO) $ 0.998990
  • tezosTezos (XTZ) $ 0.472972
  • a7a5A7A5 (A7A5) $ 0.012885
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007950
  • true-usdTrueUSD (TUSD) $ 0.997747
  • tbtctBTC (TBTC) $ 81,104.00
  • fasttokenFasttoken (FTN) $ 1.09
  • optimismOptimism (OP) $ 0.240367
  • c8ntinuumc8ntinuum (CTM) $ 0.106499
  • blockstackStacks (STX) $ 0.262460
  • chilizChiliz (CHZ) $ 0.045116
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997198
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.662916
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.190345
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 87,884.00
  • stable-2​​Stable (STABLE) $ 0.024255
  • curve-dao-tokenCurve DAO (CRV) $ 0.293470
  • gtethGTETH (GTETH) $ 2,525.32
  • euro-coinEURC (EURC) $ 1.18
  • resolv-usrResolv USR (USR) $ 0.999448
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • usdbUSDB (USDB) $ 0.982427
  • lighterLighter (LIT) $ 1.58
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,721.08
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kinesis-goldKinesis Gold (KAU) $ 157.95
  • doublezeroDoubleZero (2Z) $ 0.108227
  • msolMarinade Staked SOL (MSOL) $ 147.80
  • sbtc-2sBTC (SBTC) $ 81,737.00
  • bittorrentBitTorrent (BTT) $ 0.00000037
  • injective-protocolInjective (INJ) $ 3.65
  • lido-daoLido DAO (LDO) $ 0.429415
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 2,833.29
  • aerodrome-financeAerodrome Finance (AERO) $ 0.388451
  • syrupMaple Finance (SYRUP) $ 0.306616
  • justJUST (JST) $ 0.039926
  • ether-fiEther.fi (ETHFI) $ 0.499276
  • stader-ethxStader ETHx (ETHX) $ 2,726.73
  • flokiFLOKI (FLOKI) $ 0.000036
  • layerzeroLayerZero (ZRO) $ 1.68
  • sun-tokenSun Token (SUN) $ 0.017543
  • apenftAINFT (NFT) $ 0.00000034
  • the-graphThe Graph (GRT) $ 0.030530
  • staked-aaveStaked Aave (STKAAVE) $ 129.63
  • celestiaCelestia (TIA) $ 0.371191
  • gnosisGnosis (GNO) $ 122.36
  • axie-infinityAxie Infinity (AXS) $ 1.92
  • bitcoin-svBitcoin SV (BSV) $ 16.12
  • kaiaKaia (KAIA) $ 0.054757
  • kinesis-silverKinesis Silver (KAG) $ 85.99
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.769031
  • decredDecred (DCR) $ 18.11
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,500.36
  • pyth-networkPyth Network (PYTH) $ 0.053854
  • iotaIOTA (IOTA) $ 0.072523
  • cap-usdCap USD (CUSD) $ 1.01
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 81,333.00
  • crvusdcrvUSD (CRVUSD) $ 0.998334
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.151638

Coinbase Avoids a Major Supply Chain Attack On Its Blockchain AI Toolkit

0 87

Coinbase Avoids a Major Supply Chain Attack On Its Blockchain AI Toolkit

Coinbase, the largest crypto exchange in the US, has successfully evaded a supply chain attack that could have compromised its open-source infrastructure.

On March 23, Yu Jian, founder of blockchain security firm SlowMist, flagged the incident in a post on X, referencing a report from Unit 42, the threat intelligence division of Palo Alto Networks.

How Coinbase Stopped a Major Cyber Attack

According to Unit 42, the attacker targeted ‘agentkit’, an open-source toolkit managed by Coinbase that supports blockchain-based AI agents.

The threat actor forked agentkit and onchainkit repositories on GitHub, inserting malicious code intended to exploit the continuous integration pipeline. The suspicious activity was first detected on March 14, 2025.

“The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises,” Unit 42 reported.

The attacker exploited GitHub’s “write-all” permissions, which allowed the injection of harmful code into the project’s automated workflow. This method could have enabled access to sensitive data and created a path for broader compromises.

A Malicious Commit Targeting Coinbase. Source: Unit42

However, Unit 42 reported that the payload collected sensitive information. It did not contain advanced malicious tools like remote code execution or reverse shell exploits.

Meanwhile, Coinbase responded quickly, collaborating with security experts to isolate the threat and apply necessary mitigations. This rapid action helped the company avoid deeper infiltration and prevented potential damage to its infrastructure.

The stakes were high considering Coinbase’s standing as the largest crypto exchange in the US and a key custodian for spot Bitcoin ETFs.

A breach of this nature could have caused major disruption across the crypto industry, especially after Bybit’s recent $1.4 billion security incident.

Despite the failed attempt, the attacker has since shifted focus to a larger campaign now drawing global attention.

In light of this, SlowMist founder advised developers using GitHub Actions—especially those working with tj-actions or reviewdog—to audit their systems and confirm that no secrets have been exposed.

“If your company uses reviewdog or tj-actions, do a thorough self-examination,” Yu Jian stated on X.

This incident highlights the growing importance of securing open-source tools as the crypto ecosystem expands. Data from DeFillama shows that the crypto industry has recorded exploits of more than $1.5 billion this year.

Source

Leave A Reply

Your email address will not be published.