• bitcoinBitcoin (BTC) $ 90,605.00
  • ethereumEthereum (ETH) $ 3,007.19
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.18
  • bnbBNB (BNB) $ 880.12
  • usd-coinUSDC (USDC) $ 0.999803
  • tronTRON (TRX) $ 0.280854
  • staked-etherLido Staked Ether (STETH) $ 3,006.34
  • dogecoinDogecoin (DOGE) $ 0.149367
  • cardanoCardano (ADA) $ 0.415289
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • whitebitWhiteBIT Coin (WBT) $ 58.65
  • wrapped-stethWrapped stETH (WSTETH) $ 3,669.40
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 90,367.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,259.02
  • bitcoin-cashBitcoin Cash (BCH) $ 530.87
  • hyperliquidHyperliquid (HYPE) $ 35.42
  • usdsUSDS (USDS) $ 0.999710
  • chainlinkChainlink (LINK) $ 13.07
  • leo-tokenLEO Token (LEO) $ 9.79
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • stellarStellar (XLM) $ 0.252208
  • wethWETH (WETH) $ 3,007.87
  • wrapped-eethWrapped eETH (WEETH) $ 3,253.42
  • zcashZcash (ZEC) $ 466.48
  • moneroMonero (XMR) $ 411.27
  • ethena-usdeEthena USDe (USDE) $ 0.999510
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 90,554.00
  • litecoinLitecoin (LTC) $ 84.17
  • avalanche-2Avalanche (AVAX) $ 14.71
  • hedera-hashgraphHedera (HBAR) $ 0.143649
  • suiSui (SUI) $ 1.50
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • daiDai (DAI) $ 0.999958
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.160070
  • crypto-com-chainCronos (CRO) $ 0.108013
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • the-open-networkToncoin (TON) $ 1.58
  • paypal-usdPayPal USD (PYUSD) $ 0.999731
  • uniswapUniswap (UNI) $ 6.12
  • polkadotPolkadot (DOT) $ 2.27
  • usdt0USDT0 (USDT0) $ 0.999990
  • mantleMantle (MNT) $ 1.08
  • canton-networkCanton (CC) $ 0.082300
  • bittensorBittensor (TAO) $ 297.09
  • aaveAave (AAVE) $ 184.07
  • usd1-wlfiUSD1 (USD1) $ 0.999512
  • memecoreMemeCore (M) $ 1.50
  • bitget-tokenBitget Token (BGB) $ 3.63
  • nearNEAR Protocol (NEAR) $ 1.87
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • okbOKB (OKB) $ 107.40
  • internet-computerInternet Computer (ICP) $ 4.10
  • aster-2Aster (ASTER) $ 1.10
  • tether-goldTether Gold (XAUT) $ 4,216.78
  • falcon-financeFalcon USD (USDF) $ 0.999337
  • ethereum-classicEthereum Classic (ETC) $ 13.69
  • ethenaEthena (ENA) $ 0.279662
  • pi-networkPi Network (PI) $ 0.244449
  • jito-staked-solJito Staked SOL (JITOSOL) $ 170.55
  • pepePepe (PEPE) $ 0.000005
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,008.15
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.69
  • pump-funPump.fun (PUMP) $ 0.002878
  • solanaSolana (SOL) $ 136.87
  • rainRain (RAIN) $ 0.006972
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ondo-financeOndo (ONDO) $ 0.511925
  • aptosAptos (APT) $ 2.09
  • kaspaKaspa (KAS) $ 0.056834
  • worldcoin-wldWorldcoin (WLD) $ 0.638885
  • kucoin-sharesKuCoin (KCS) $ 11.67
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.134272
  • pax-goldPAX Gold (PAXG) $ 4,236.19
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • quant-networkQuant (QNT) $ 93.23
  • usdtbUSDtb (USDTB) $ 1.00
  • bfusdBFUSD (BFUSD) $ 0.999081
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999816
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,454.37
  • ripple-usdRipple USD (RLUSD) $ 0.999989
  • algorandAlgorand (ALGO) $ 0.141139
  • gatechain-tokenGate (GT) $ 10.58
  • global-dollarGlobal Dollar (USDG) $ 0.999779
  • wbnbWrapped BNB (WBNB) $ 880.22
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • arbitrumArbitrum (ARB) $ 0.214905
  • official-trumpOfficial Trump (TRUMP) $ 6.03
  • skySky (SKY) $ 0.052035
  • flare-networksFlare (FLR) $ 0.015140
  • cosmosCosmos Hub (ATOM) $ 2.42
  • binance-staked-solBinance Staked SOL (BNSOL) $ 148.25
  • filecoinFilecoin (FIL) $ 1.60
  • vechainVeChain (VET) $ 0.013375
  • hash-2Provenance Blockchain (HASH) $ 0.022180
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 35.65
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,181.53
  • ignition-fbtcFunction FBTC (FBTC) $ 90,765.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,567.00
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,217.35
  • xdce-crowd-saleXDC Network (XDC) $ 0.053575
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • nexoNEXO (NEXO) $ 0.984646
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 90,455.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996704
  • render-tokenRender (RENDER) $ 1.77
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.91
  • sei-networkSei (SEI) $ 0.136247
  • story-2Story (IP) $ 2.52
  • morphoMorpho (MORPHO) $ 1.52
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.37
  • bonkBonk (BONK) $ 0.000010
  • ousgOUSG (OUSG) $ 113.47
  • jupiter-exchange-solanaJupiter (JUP) $ 0.244989
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,250.76
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,200.21
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 90,407.00
  • dashDash (DASH) $ 56.74
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.269396
  • clbtcclBTC (CLBTC) $ 90,661.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010969
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 158.04
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999803
  • optimismOptimism (OP) $ 0.327909
  • starknetStarknet (STRK) $ 0.136063
  • spx6900SPX6900 (SPX) $ 0.665388
  • usdaiUSDai (USDAI) $ 1.00
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999986
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.934369
  • aerodrome-financeAerodrome Finance (AERO) $ 0.677023
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,129.24
  • curve-dao-tokenCurve DAO (CRV) $ 0.425341
  • beldexBeldex (BDX) $ 0.081137
  • injective-protocolInjective (INJ) $ 5.98
  • lido-daoLido DAO (LDO) $ 0.655020
  • blockstackStacks (STX) $ 0.315567
  • tbtctBTC (TBTC) $ 90,443.00
  • newton-projectAB (AB) $ 0.006290
  • msolMarinade Staked SOL (MSOL) $ 183.86
  • usual-usdUsual USD (USD0) $ 0.997588
  • celestiaCelestia (TIA) $ 0.636583
  • the-graphThe Graph (GRT) $ 0.050672
  • tezosTezos (XTZ) $ 0.503451
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,006.37
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,007.87
  • ether-fiEther.fi (ETHFI) $ 0.827735
  • true-usdTrueUSD (TUSD) $ 0.996449
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • myx-financeMYX Finance (MYX) $ 2.52
  • usddUSDD (USDD) $ 1.00
  • iotaIOTA (IOTA) $ 0.113120
  • flokiFLOKI (FLOKI) $ 0.000048
  • telcoinTelcoin (TEL) $ 0.004866
  • gtethGTETH (GTETH) $ 3,006.92
  • kaiaKaia (KAIA) $ 0.078776
  • stader-ethxStader ETHx (ETHX) $ 3,233.13
  • pendlePendle (PENDLE) $ 2.72
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • ethereum-name-serviceEthereum Name Service (ENS) $ 11.67
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,177.10
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.04
  • pyth-networkPyth Network (PYTH) $ 0.075190
  • plasmaPlasma (XPL) $ 0.218355
  • conflux-tokenConflux (CFX) $ 0.082392
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • decredDecred (DCR) $ 24.59
  • ghoGHO (GHO) $ 0.999953
  • sonic-3Sonic (S) $ 0.109322
  • monadMonad (MON) $ 0.037759
  • bitcoin-svBitcoin SV (BSV) $ 20.76
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • the-sandboxThe Sandbox (SAND) $ 0.157239
  • basic-attention-tokenBasic Attention (BAT) $ 0.272262
  • sun-tokenSun Token (SUN) $ 0.021132
  • usdbUSDB (USDB) $ 0.997313
  • doublezeroDoubleZero (2Z) $ 0.115439
  • swethSwell Ethereum (SWETH) $ 3,292.07
  • heliumHelium (HNT) $ 2.14
  • wrapped-hypeWrapped HYPE (WHYPE) $ 35.51
  • sbtc-2sBTC (SBTC) $ 90,016.00
  • justJUST (JST) $ 0.039347
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,327.29
  • apenftAINFT (NFT) $ 0.00000039
  • fasttokenFasttoken (FTN) $ 0.882123
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.149305
  • flowFlow (FLOW) $ 0.233250
  • merlin-chainMerlin Chain (MERL) $ 0.360842
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 90,621.00
  • dogwifcoindogwifhat (WIF) $ 0.374069
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 18.13
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,005.44
  • olympusOlympus (OHM) $ 22.28
  • galaGALA (GALA) $ 0.007786
  • ultimaUltima (ULTIMA) $ 3,632.77
  • jasmycoinJasmyCoin (JASMY) $ 0.007281

Phantom is safe from Solana Web3.js vulnerability; users are advised to upgrade soon

0 181

Phantom is safe from Solana Web3.js vulnerability; users are advised to upgrade soon

Phantom has confirmed that it has not been affected by a vulnerability discovered in the Solana library, i.e. Solana/web3.js.

Phantom, a wallet provider running on the Solana (SOL) blockchain, confirmed it is safe after a recent vulnerability was discovered in the Solana/Web3.js library. According to a statement posted on X, the Phantom security team verified that the compromised versions of the library- 1.95.6 and 1.95.7 – will never be utilized in their infrastructure, assuring their users that their platform is secured.

anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected)

if you run a service that can blacklist addresses, do your thing with…

— trent.sol (@trentdotsol) December 3, 2024

Do not use @solana/web3.js versions 1.95.6 and 1.95.7., writes Trent.sol on his X profile. You might also like: Celcius founder plead guilty due to fraud charges

Earlier today, Trent Sol, a Solana developer, warned users about the compromised library. He informed users that these versions could put users at risk of secret stealer attacks, which are capable of leaking private keys used to access and secure wallets. Products and developers using the compromised versions should upgrade to version 1.95.8., urged Trent. However, previous versions, such as 1.95.5, remain unaffected by the issues.

Phantom is not impacted by this vulnerability.

Our Security Team confirms that we have never used the exploited versions of @solana/web3.js https://t.co/9wHZ4cnwa1

— Phantom (@phantom) December 3, 2024

Phantom acknowledges that it is safe from solana/web3.js vulnerabilities.

Solana ecosystem addresses Web3.js vulnerability

The Solana ecosystem has been quick to respond to addressing the vulnerability. Important projects such as Drift, Phantom, and Solflare have informed their communities that they are not affected as they either do not put to use the compromised version or have other security measures that keep them safe. The ecosystem’s developers and projects are also urged to check their dependencies and update their libraries to ensure funds and data remain secure.

Rise in vulnerabilities

Trent Sol’s disclosure of vulnerability reflects a larger challenge of security that blockchain ecosystems often have to tackle. Forensic analysis shows that the broken versions of the library held hidden commands meant to capture and transmit private keys to a wallet named FnvLGtucz4E1ppJHRTev6Qv4X7g8Pw6WPStHCcbAKbfx. Cloud security researcher Christophe Tafani-Dereeper from Datadog underscored the sophistication of the backdoor at Bluesky.

Exclusive: The backdoor inserted in v1.95.7 adds an “addToQueue” function which exfiltrates the private key through seemingly-legitimate CloudFlare headers.Calls to this function are then inserted in various places that (legitimately) access the private key.

— Christophe Tafani-Dereeper (@christophetd.fr) 2024-12-03T23:47:18.004Z

Developer Tafani-Dereeper does forensic analysis of the solana/web3.js vulnerabilities. You might also like: ‘Bitcoin Jesus’ Roger Ver fights indictment and accuses U.S. government of overreach

Such risks have become increasingly common, as evidenced by a malicious package incident earlier this year, reported by The Hacker News, involving the Python Package Index, commonly known as PyPl. The package, “solana-py“, masqueraded as the legitimate Solana Python API to steal Solana wallet keys and exfiltrate them to an attacker-controlled server. It also exploited naming similarities to trick developers, leading to 1,122 downloads before its removal.

Read more: What DePIN got wrong and how to fix it | Opinion

Source

Leave A Reply

Your email address will not be published.