• bitcoinBitcoin (BTC) $ 111,440.00
  • ethereumEthereum (ETH) $ 3,952.43
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.61
  • bnbBNB (BNB) $ 1,114.59
  • solanaSolana (SOL) $ 193.90
  • usd-coinUSDC (USDC) $ 0.999900
  • staked-etherLido Staked Ether (STETH) $ 3,951.16
  • dogecoinDogecoin (DOGE) $ 0.196667
  • tronTRON (TRX) $ 0.297790
  • cardanoCardano (ADA) $ 0.656632
  • wrapped-stethWrapped stETH (WSTETH) $ 4,792.97
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 111,148.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,243.29
  • chainlinkChainlink (LINK) $ 18.11
  • hyperliquidHyperliquid (HYPE) $ 43.10
  • wrapped-eethWrapped eETH (WEETH) $ 4,244.58
  • ethena-usdeEthena USDe (USDE) $ 0.997798
  • stellarStellar (XLM) $ 0.326947
  • bitcoin-cashBitcoin Cash (BCH) $ 507.14
  • suiSui (SUI) $ 2.55
  • usdsUSDS (USDS) $ 0.999701
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • wethWETH (WETH) $ 3,931.11
  • avalanche-2Avalanche (AVAX) $ 19.70
  • leo-tokenLEO Token (LEO) $ 9.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 111,237.00
  • litecoinLitecoin (LTC) $ 96.78
  • hedera-hashgraphHedera (HBAR) $ 0.173170
  • usdt0USDT0 (USDT0) $ 1.00
  • moneroMonero (XMR) $ 338.04
  • whitebitWhiteBIT Coin (WBT) $ 42.40
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • crypto-com-chainCronos (CRO) $ 0.152083
  • the-open-networkToncoin (TON) $ 2.16
  • mantleMantle (MNT) $ 1.66
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • polkadotPolkadot (DOT) $ 3.09
  • daiDai (DAI) $ 0.997780
  • zcashZcash (ZEC) $ 272.16
  • memecoreMemeCore (M) $ 2.25
  • uniswapUniswap (UNI) $ 6.26
  • bittensorBittensor (TAO) $ 388.69
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.136958
  • okbOKB (OKB) $ 167.03
  • aaveAave (AAVE) $ 226.87
  • susdssUSDS (SUSDS) $ 1.06
  • ethenaEthena (ENA) $ 0.467693
  • bitget-tokenBitget Token (BGB) $ 4.68
  • pepePepe (PEPE) $ 0.000007
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.29
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999644
  • jito-staked-solJito Staked SOL (JITOSOL) $ 241.04
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.190997
  • ethereum-classicEthereum Classic (ETC) $ 16.01
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,954.64
  • aptosAptos (APT) $ 3.30
  • ondo-financeOndo (ONDO) $ 0.738549
  • aster-2Aster (ASTER) $ 1.13
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.51
  • falcon-financeFalcon USD (USDF) $ 0.997369
  • tether-goldTether Gold (XAUT) $ 4,120.66
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.196199
  • worldcoin-wldWorldcoin (WLD) $ 0.895784
  • usdtbUSDtb (USDTB) $ 0.995836
  • gatechain-tokenGate (GT) $ 15.53
  • arbitrumArbitrum (ARB) $ 0.321059
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,504.15
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pi-networkPi Network (PI) $ 0.207798
  • kucoin-sharesKuCoin (KCS) $ 13.29
  • binance-staked-solBinance Staked SOL (BNSOL) $ 209.18
  • story-2Story (IP) $ 5.25
  • internet-computerInternet Computer (ICP) $ 3.13
  • hash-2Provenance Blockchain (HASH) $ 0.032868
  • algorandAlgorand (ALGO) $ 0.185905
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 43.31
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,154.13
  • cosmosCosmos Hub (ATOM) $ 3.16
  • vechainVeChain (VET) $ 0.017324
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,151.37
  • kaspaKaspa (KAS) $ 0.055500
  • pump-funPump.fun (PUMP) $ 0.004130
  • chainopera-aiChainOpera AI (COAI) $ 7.40
  • wbnbWrapped BNB (WBNB) $ 1,114.17
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,202.73
  • jupiter-exchange-solanaJupiter (JUP) $ 0.430529
  • pax-goldPAX Gold (PAXG) $ 4,108.42
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.021542
  • skySky (SKY) $ 0.058207
  • bfusdBFUSD (BFUSD) $ 0.999900
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 111,388.00
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • flare-networksFlare (FLR) $ 0.016963
  • render-tokenRender (RENDER) $ 2.49
  • sei-networkSei (SEI) $ 0.201321
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,177.49
  • official-trumpOfficial Trump (TRUMP) $ 6.00
  • bonkBonk (BONK) $ 0.000015
  • nexoNEXO (NEXO) $ 1.14
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 110,536.00
  • xdce-crowd-saleXDC Network (XDC) $ 0.062718
  • filecoinFilecoin (FIL) $ 1.57
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.10
  • immutable-xImmutable (IMX) $ 0.539465
  • morphoMorpho (MORPHO) $ 2.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.993043
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,252.63
  • spx6900SPX6900 (SPX) $ 1.05
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 222.53
  • global-dollarGlobal Dollar (USDG) $ 0.999810
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.69
  • ripple-usdRipple USD (RLUSD) $ 0.996602
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 110,846.00
  • celestiaCelestia (TIA) $ 1.05
  • clbtcclBTC (CLBTC) $ 111,240.00
  • optimismOptimism (OP) $ 0.449318
  • doublezeroDoubleZero (2Z) $ 0.242170
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.28
  • aerodrome-financeAerodrome Finance (AERO) $ 0.923005
  • lido-daoLido DAO (LDO) $ 0.925895
  • injective-protocolInjective (INJ) $ 8.45
  • msolMarinade Staked SOL (MSOL) $ 258.57
  • blockstackStacks (STX) $ 0.448743
  • fasttokenFasttoken (FTN) $ 1.86
  • ousgOUSG (OUSG) $ 113.06
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.87
  • curve-dao-tokenCurve DAO (CRV) $ 0.536016
  • plasmaPlasma (XPL) $ 0.387282
  • flokiFLOKI (FLOKI) $ 0.000074
  • the-graphThe Graph (GRT) $ 0.065279
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 4,154.86
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,946.59
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998658
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.261654
  • pyth-networkPyth Network (PYTH) $ 0.115898
  • tbtctBTC (TBTC) $ 110,814.00
  • tezosTezos (XTZ) $ 0.604370
  • kaiaKaia (KAIA) $ 0.108390
  • sonic-3Sonic (S) $ 0.167169
  • humanityHumanity (H) $ 0.344831
  • gtethGTETH (GTETH) $ 3,942.64
  • iotaIOTA (IOTA) $ 0.147378
  • stader-ethxStader ETHx (ETHX) $ 4,214.33
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,931.25
  • usdaiUSDai (USDAI) $ 1.01
  • beldexBeldex (BDX) $ 0.078190
  • ether-fiEther.fi (ETHFI) $ 1.03
  • newton-projectAB (AB) $ 0.006911
  • conflux-tokenConflux (CFX) $ 0.111034
  • myx-financeMYX Finance (MYX) $ 2.97
  • theta-tokenTheta Network (THETA) $ 0.552217
  • dogwifcoindogwifhat (WIF) $ 0.550634
  • usual-usdUsual USD (USD0) $ 0.996822
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 1.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999903
  • pendlePendle (PENDLE) $ 3.20
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,335.36
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.28
  • swethSwell Ethereum (SWETH) $ 4,336.86
  • the-sandboxThe Sandbox (SAND) $ 0.214536
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 111,484.00
  • starknetStarknet (STRK) $ 0.120319
  • jasmycoinJasmyCoin (JASMY) $ 0.010723
  • dashDash (DASH) $ 41.36
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.55
  • galaGALA (GALA) $ 0.011136
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.998513
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.196945
  • bittorrentBitTorrent (BTT) $ 0.00000050
  • true-usdTrueUSD (TUSD) $ 0.995342
  • raydiumRaydium (RAY) $ 1.80
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,932.85
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • vaultaVaulta (A) $ 0.294275
  • swissborgSwissBorg (BORG) $ 0.474913
  • decentralandDecentraland (MANA) $ 0.241890
  • usddUSDD (USDD) $ 1.00
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 24.18
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,238.94
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,178.12
  • jito-governance-tokenJito (JTO) $ 1.14
  • flowFlow (FLOW) $ 0.274057
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,247.22
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.11
  • bitcoin-svBitcoin SV (BSV) $ 21.62
  • syrupMaple Finance (SYRUP) $ 0.384718
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,946.49
  • sun-tokenSun Token (SUN) $ 0.022402
  • wrapped-hypeWrapped HYPE (WHYPE) $ 43.21
  • havvenSynthetix (SNX) $ 1.23
  • satoshi-stablecoinSatoshi Stablecoin (SATUSD) $ 1.00
  • zoraZora (ZORA) $ 0.094329
  • apecoinApeCoin (APE) $ 0.451199
  • ghoGHO (GHO) $ 0.999557

Explained: how crypto’s ‘largest supply chain attack’ stole just $0.05

0 24

Explained: how crypto’s ‘largest supply chain attack’ stole just $0.05

A widespread security supply chain attack led to panic across the crypto community yesterday with users warned to “refrain from making any on-chain transactions.”

Researchers at security firm Aikido raised the alarm after discovering that 18 popular node package manager (npm) packages contained malicious code.

After being notified, the developer who maintains the popular npm packages, alias Qix, confirmed the compromise. He’d been “pwned” via a phishing email which “looked very legitimate.”

Despite the packages being widespread across the crypto industry, the attack led to almost no losses.

Samczsun, the head of Security Alliance, a blockchain security collective, called the result a “generational fumble.”

What is an npm compromise?

While short-lived, the compromise was far reaching, due to the sheer frequency at which packages such as “chalk” and “debug-js” are used.

Analysis of the incident by Security Alliance stated that the compromised packages total “over 2 billion downloads per week.” It called the incident “likely the largest supply chain attack in history.”

In theory, the compromised packages could be used to modify transaction data for crypto users.

The Aikido report explains how the code “intercepts crypto and web3 activity in the browser” before it “rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user.”

In an effort to camouflage the substituted addresses, the code uses the Levenshtein distance algorithm. This identifies visually similar attacker-controlled addresses to be injected in each attack.

The technique is similar to the often costly address poisoning attacks which plague the industry.

So, was the panic justified?

Warnings came in many forms. Some opted for measured recommendations to avoid signing transactions. Others made tongue in cheek claims that “THE BLOCKCHAIN IS COMPROMISED.”

MetaMask, crypto’s most popular browser wallet, took to X to reassure users not to be “scared” of the attack. They detailed three “layers of defense” in place “to protect our products and users.”

0xngmi, the pseudonymous developer of decentralized finance dashboard DeFiLlama, explained that malicious packages would “only impact websites that pushed an update since the hacked npm package was published,” adding “most projects pin their dependencies, so even if they push an update they’ll keep using the old safe code.”

In all, the compromised packages were up for around two and a half hours. While the issue is marked as resolved on GitHub, Qix warns “other maintainers have been affected. Stay vigilant.”

The ‘dust’ settles

Once it became clear that the danger was limited, the community turned its focus to the attacker’s addresses.

Security Alliance identified a grand total of “around five cents of ETH” directly stolen during the attack.

Etherscan data show that the main address’ holdings are worth just over $900. However, around half that is 0.1 ETH, sent this morning, and various memecoins transferred for visibility.

Ridicule even came on-chain with one transaction input data message calling the attacker a “bloody fool.” The user made fun of the hacker who “hacked a massive npm developer account and still [couldn’t] steal [a] single penny. You are such a looser [sic].”

Security researchers took a moment to reflect, worrying that the bungled attempt may have “shown the way” for copycats.

The Security Alliance X account says the industry “got lucky.” A “stealthily deployed backdoor” targeting developers could have persisted for long enough to be integrated into crypto apps.

Its incident report points to the true cost as the wasted “hours spent by engineering and security teams” and the “sales contracts that will inevitably be signed as a result of this new case study.”

Source

Leave A Reply

Your email address will not be published.