• bitcoinBitcoin (BTC) $ 76,511.00
  • ethereumEthereum (ETH) $ 2,263.08
  • tetherTether (USDT) $ 0.999467
  • xrpXRP (XRP) $ 1.37
  • bnbBNB (BNB) $ 616.30
  • usd-coinUSDC (USDC) $ 0.999676
  • solanaSolana (SOL) $ 83.31
  • tronTRON (TRX) $ 0.327102
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.107633
  • whitebitWhiteBIT Coin (WBT) $ 57.32
  • usdsUSDS (USDS) $ 0.999763
  • hyperliquidHyperliquid (HYPE) $ 40.13
  • leo-tokenLEO Token (LEO) $ 10.31
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.246618
  • bitcoin-cashBitcoin Cash (BCH) $ 441.30
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 381.13
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.12
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • zcashZcash (ZEC) $ 348.95
  • canton-networkCanton (CC) $ 0.150568
  • stellarStellar (XLM) $ 0.158531
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999461
  • daiDai (DAI) $ 0.999685
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 55.21
  • memecoreMemeCore (M) $ 3.19
  • avalanche-2Avalanche (AVAX) $ 9.11
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • ethena-usdeEthena USDe (USDE) $ 0.999053
  • hedera-hashgraphHedera (HBAR) $ 0.087659
  • rainRain (RAIN) $ 0.007829
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • suiSui (SUI) $ 0.909315
  • the-open-networkToncoin (TON) $ 1.35
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 0.999766
  • crypto-com-chainCronos (CRO) $ 0.068416
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,607.92
  • global-dollarGlobal Dollar (USDG) $ 0.999760
  • bittensorBittensor (TAO) $ 250.39
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • pax-goldPAX Gold (PAXG) $ 4,611.59
  • mantleMantle (MNT) $ 0.626865
  • uniswapUniswap (UNI) $ 3.20
  • polkadotPolkadot (DOT) $ 1.21
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.060579
  • pi-networkPi Network (PI) $ 0.179637
  • skySky (SKY) $ 0.079651
  • falcon-financeFalcon USD (USDF) $ 0.996864
  • okbOKB (OKB) $ 82.65
  • aster-2Aster (ASTER) $ 0.652566
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • nearNEAR Protocol (NEAR) $ 1.30
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • usddUSDD (USDD) $ 0.999708
  • ripple-usdRipple USD (RLUSD) $ 0.999849
  • aaveAave (AAVE) $ 92.98
  • bitget-tokenBitget Token (BGB) $ 1.99
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • bfusdBFUSD (BFUSD) $ 0.998698
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • internet-computerInternet Computer (ICP) $ 2.38
  • ethereum-classicEthereum Classic (ETC) $ 8.37
  • ondo-financeOndo (ONDO) $ 0.262990
  • morphoMorpho (MORPHO) $ 2.02
  • kucoin-sharesKuCoin (KCS) $ 8.45
  • united-stablesUnited Stables (U) $ 0.999722
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.094648
  • quant-networkQuant (QNT) $ 68.97
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • algorandAlgorand (ALGO) $ 0.109967
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.07
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.75
  • cosmosCosmos Hub (ATOM) $ 1.88
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • ethenaEthena (ENA) $ 0.103076
  • nexoNEXO (NEXO) $ 0.896715
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.032512
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.68
  • gatechain-tokenGate (GT) $ 7.23
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • aptosAptos (APT) $ 1.00
  • worldcoin-wldWorldcoin (WLD) $ 0.243882
  • wbnbWrapped BNB (WBNB) $ 759.61
  • arbitrumArbitrum (ARB) $ 0.124004
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • justJUST (JST) $ 0.088991
  • stable-2​​Stable (STABLE) $ 0.033476
  • filecoinFilecoin (FIL) $ 0.924066
  • flare-networksFlare (FLR) $ 0.007471
  • pump-funPump.fun (PUMP) $ 0.001779
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010031
  • beldexBeldex (BDX) $ 0.079850
  • ousgOUSG (OUSG) $ 115.09
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007016
  • hash-2Provenance Blockchain (HASH) $ 0.011444
  • jupiter-exchange-solanaJupiter (JUP) $ 0.180390
  • xdce-crowd-saleXDC Network (XDC) $ 0.029745
  • usdtbUSDtb (USDTB) $ 1.00
  • ghoGHO (GHO) $ 0.999512
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.999043
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • official-trumpOfficial Trump (TRUMP) $ 2.39
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • midnight-3Midnight (NIGHT) $ 0.032719
  • bonkBonk (BONK) $ 0.000006
  • dexeDeXe (DEXE) $ 11.47
  • clbtcclBTC (CLBTC) $ 76,920.00
  • yldsYLDS (YLDS) $ 0.999998
  • true-usdTrueUSD (TUSD) $ 0.999247
  • siren-2Siren (SIREN) $ 0.674601
  • a7a5A7A5 (A7A5) $ 0.012308
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.45
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.691892
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • dashDash (DASH) $ 35.18
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.195863
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • euro-coinEURC (EURC) $ 1.17
  • chilizChiliz (CHZ) $ 0.041647
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • adi-tokenADI (ADI) $ 4.07
  • aerodrome-financeAerodrome Finance (AERO) $ 0.449886
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000075
  • blockstackStacks (STX) $ 0.221250
  • edgexedgeX (EDGE) $ 1.16
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998499
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • tezosTezos (XTZ) $ 0.364767
  • venice-tokenVenice Token (VVV) $ 8.57
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • sei-networkSei (SEI) $ 0.057302
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • usxUSX (USX) $ 0.999637
  • cocaCOCA (COCA) $ 1.30
  • manadiaManadia (UMXM) $ 1.75
  • skyaiSkyAI (SKYAI) $ 0.366298
  • layerzeroLayerZero (ZRO) $ 1.44
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • megausdMegaUSD (USDM) $ 0.999781
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • sun-tokenSun Token (SUN) $ 0.018538
  • curve-dao-tokenCurve DAO (CRV) $ 0.235854
  • kinesis-goldKinesis Gold (KAU) $ 147.42
  • injective-protocolInjective (INJ) $ 3.45
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • ether-fiEther.fi (ETHFI) $ 0.411549
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.340889
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • spx6900SPX6900 (SPX) $ 0.364627
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • zebec-networkZebec Network (ZBCN) $ 0.003401
  • humanityHumanity (H) $ 0.180817
  • hastra-primePRIME (PRIME) $ 1.03
  • monadMonad (MON) $ 0.027407
  • gnosisGnosis (GNO) $ 122.52
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • celestiaCelestia (TIA) $ 0.349569
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • bitcoin-svBitcoin SV (BSV) $ 15.79
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • decredDecred (DCR) $ 18.18
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • apenftAINFT (NFT) $ 0.00000032
  • lido-daoLido DAO (LDO) $ 0.367827
  • flokiFLOKI (FLOKI) $ 0.000032
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • conflux-tokenConflux (CFX) $ 0.059084
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • usdgoUSDGO (USDGO) $ 0.999897
  • olympusOlympus (OHM) $ 19.10
  • doublezeroDoubleZero (2Z) $ 0.082110
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • crvusdcrvUSD (CRVUSD) $ 0.999572
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Crypto devs face new threat from Claude-based malware

0 2

Crypto devs face new threat from Claude-based malware

An open-source crypto trading project received a malicious npm package called @validate-sdk/v2 after Anthropic’s Claude Opus AI model made it a dependency. This gave hackers access to users’ crypto wallets and funds.

Security researchers from ReversingLabs (RL) found the breach in the openpaw-graveyard project, which is an autonomous crypto trading agent hosted on npm. They called it PromptMink.

The bad commit was made on February 28, 2026. ReversingLabs says that the package pretends to be a tool for checking data but really steals secrets from the host environment.

North Korean hackers linked to PromptMink malware

ReversingLabs said that the attack came from Famous Chollima, a North Korean state-sponsored threat group.

The group has been spreading malicious npm packages since at least September 2025. They have been improving a two-layer strategy that is meant to trick both human devs and AI coding assistants.

The first layer is made up of packages that don’t have any malicious code. These “bait” packages, like @solana-launchpad/sdk and @meme-sdk/trade, seem like real tools for crypto developers.

They list a few second-layer packages that carry the actual payload, along with popular npm packages like axios and bn.js as dependencies.

When the second-layer packages are reported and taken down from npm, the attackers just put in a new one without losing the reputation they’ve built around the bait packages.

ReversingLabs says that when @hash-validator/v2 was taken off of npm, the attackers released @validate-sdk/v2 the same day with the same version number and source code.

AI agents are more susceptible to hacks than humans

Security researchers stated that Famous Chollima’s method seems more suited to taking advantage of AI coding assistants than human developers. The group writes long, detailed documentation for its malicious packages, which researchers call “LLM Optimization abuse.”

The goal is to make packages look real enough that AI agents will suggest and install them without any problems. The infected packages were “vibe-coded” by generative AI tools. Leftover LLM responses are visible in the file comments.

Since late 2025, the PromptMink malware has taken on many different forms.

It started as a simple JavaScript infostealer, then grew into big single-executable applications, and now comes as compiled Rust payloads that are made to be stealthy, according to ReversingLabs.

When the malware is installed, it looks for configuration files related to crypto, steals wallet credentials and system information, compresses and sends project source code to itself, and drops SSH keys on Linux and Windows machines so it can always access them remotely.

The PromptMink campaign is not the only recent attack targeting crypto developers through package managers.

Last month, Cryptopolitan reported on GhostClaw, a malware that targeted the OpenClaw community through a fake npm installer. It harvested crypto wallet data, macOS Keychain passwords, and AI platform API tokens from 178 developers before removal from the npm registry.

PromptMink and GhostClaw use social engineering as an entry point and target developers working in crypto and Web3. What makes PromptMink different is that it targets AI coding agents and uses them as the attack path.

Source

Leave A Reply

Your email address will not be published.