• bitcoinBitcoin (BTC) $ 92,600.00
  • ethereumEthereum (ETH) $ 3,349.18
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 899.71
  • xrpXRP (XRP) $ 2.05
  • usd-coinUSDC (USDC) $ 0.998715
  • staked-etherLido Staked Ether (STETH) $ 3,344.69
  • tronTRON (TRX) $ 0.280623
  • dogecoinDogecoin (DOGE) $ 0.144818
  • cardanoCardano (ADA) $ 0.457607
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • whitebitWhiteBIT Coin (WBT) $ 63.38
  • wrapped-stethWrapped stETH (WSTETH) $ 4,086.95
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,637.02
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 92,341.00
  • bitcoin-cashBitcoin Cash (BCH) $ 577.78
  • chainlinkChainlink (LINK) $ 14.28
  • usdsUSDS (USDS) $ 0.998735
  • wrapped-eethWrapped eETH (WEETH) $ 3,622.87
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • wethWETH (WETH) $ 3,344.36
  • leo-tokenLEO Token (LEO) $ 9.51
  • stellarStellar (XLM) $ 0.251954
  • hyperliquidHyperliquid (HYPE) $ 29.49
  • moneroMonero (XMR) $ 398.12
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 92,486.00
  • zcashZcash (ZEC) $ 406.55
  • ethena-usdeEthena USDe (USDE) $ 0.999543
  • litecoinLitecoin (LTC) $ 85.02
  • avalanche-2Avalanche (AVAX) $ 14.29
  • suiSui (SUI) $ 1.62
  • hedera-hashgraphHedera (HBAR) $ 0.136258
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • usdt0USDT0 (USDT0) $ 1.00
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999418
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.153876
  • the-open-networkToncoin (TON) $ 1.68
  • crypto-com-chainCronos (CRO) $ 0.104157
  • paypal-usdPayPal USD (PYUSD) $ 0.999693
  • mantleMantle (MNT) $ 1.16
  • polkadotPolkadot (DOT) $ 2.22
  • uniswapUniswap (UNI) $ 5.70
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • aaveAave (AAVE) $ 198.62
  • bittensorBittensor (TAO) $ 299.78
  • usd1-wlfiUSD1 (USD1) $ 0.999240
  • rainRain (RAIN) $ 0.008018
  • canton-networkCanton (CC) $ 0.074774
  • bitget-tokenBitget Token (BGB) $ 3.59
  • okbOKB (OKB) $ 119.14
  • memecoreMemeCore (M) $ 1.43
  • nearNEAR Protocol (NEAR) $ 1.78
  • falcon-financeFalcon USD (USDF) $ 0.998941
  • tether-goldTether Gold (XAUT) $ 4,219.04
  • ethereum-classicEthereum Classic (ETC) $ 13.80
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,346.29
  • ethenaEthena (ENA) $ 0.260752
  • aster-2Aster (ASTER) $ 0.955262
  • pepePepe (PEPE) $ 0.000005
  • jito-staked-solJito Staked SOL (JITOSOL) $ 171.17
  • internet-computerInternet Computer (ICP) $ 3.50
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.213716
  • pump-funPump.fun (PUMP) $ 0.002914
  • solanaWrapped SOL (SOL) $ 137.31
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.76
  • ondo-financeOndo (ONDO) $ 0.494719
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • worldcoin-wldWorldcoin (WLD) $ 0.623043
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pax-goldPAX Gold (PAXG) $ 4,237.40
  • kucoin-sharesKuCoin (KCS) $ 10.80
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,842.92
  • midnight-3Midnight (NIGHT) $ 0.085553
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,343.73
  • global-dollarGlobal Dollar (USDG) $ 0.999770
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • hash-2Provenance Blockchain (HASH) $ 0.025719
  • aptosAptos (APT) $ 1.80
  • kaspaKaspa (KAS) $ 0.049380
  • bfusdBFUSD (BFUSD) $ 0.999371
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.124649
  • ripple-usdRipple USD (RLUSD) $ 0.999716
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999794
  • skySky (SKY) $ 0.055944
  • quant-networkQuant (QNT) $ 84.88
  • gatechain-tokenGate (GT) $ 10.56
  • arbitrumArbitrum (ARB) $ 0.218872
  • wbnbWrapped BNB (WBNB) $ 899.25
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,542.28
  • algorandAlgorand (ALGO) $ 0.136624
  • binance-staked-solBinance Staked SOL (BNSOL) $ 149.33
  • official-trumpOfficial Trump (TRUMP) $ 5.75
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,583.57
  • cosmosCosmos Hub (ATOM) $ 2.28
  • filecoinFilecoin (FIL) $ 1.49
  • vechainVeChain (VET) $ 0.012423
  • ignition-fbtcFunction FBTC (FBTC) $ 91,752.00
  • flare-networksFlare (FLR) $ 0.012822
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 92,515.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 92,170.00
  • nexoNEXO (NEXO) $ 0.985735
  • xdce-crowd-saleXDC Network (XDC) $ 0.050152
  • sei-networkSei (SEI) $ 0.145646
  • render-tokenRender (RENDER) $ 1.66
  • usdtbUSDtb (USDTB) $ 1.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,565.00
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 29.59
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.92
  • bonkBonk (BONK) $ 0.000010
  • ousgOUSG (OUSG) $ 113.59
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,615.47
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.34
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999857
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.011990
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998202
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 92,438.00
  • wrapped-flareWrapped Flare (WFLR) $ 0.012812
  • jupiter-exchange-solanaJupiter (JUP) $ 0.229308
  • clbtcclBTC (CLBTC) $ 92,208.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999747
  • story-2Story (IP) $ 2.10
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • morphoMorpho (MORPHO) $ 1.24
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.256521
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 158.71
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,457.06
  • ultimaUltima (ULTIMA) $ 6,473.57
  • usdaiUSDai (USDAI) $ 1.00
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999874
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,343.61
  • optimismOptimism (OP) $ 0.327172
  • beldexBeldex (BDX) $ 0.086985
  • spx6900SPX6900 (SPX) $ 0.637277
  • curve-dao-tokenCurve DAO (CRV) $ 0.412993
  • dashDash (DASH) $ 47.17
  • aerodrome-financeAerodrome Finance (AERO) $ 0.650709
  • injective-protocolInjective (INJ) $ 5.74
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.853587
  • lido-daoLido DAO (LDO) $ 0.627219
  • blockstackStacks (STX) $ 0.308344
  • tbtctBTC (TBTC) $ 91,981.00
  • usual-usdUsual USD (USD0) $ 0.999042
  • myx-financeMYX Finance (MYX) $ 2.84
  • gtethGTETH (GTETH) $ 3,351.35
  • tezosTezos (XTZ) $ 0.497487
  • starknetStarknet (STRK) $ 0.109255
  • bridged-wrapped-ether-pundi-aifx-omnilayerBridged Wrapped Ether (Pundi AIFX Omnilayer) (WETH) $ 35,382,014.00
  • celestiaCelestia (TIA) $ 0.612803
  • ether-fiEther.fi (ETHFI) $ 0.850286
  • telcoinTelcoin (TEL) $ 0.005404
  • stader-ethxStader ETHx (ETHX) $ 3,599.26
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,346.90
  • true-usdTrueUSD (TUSD) $ 0.998608
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,460.42
  • the-graphThe Graph (GRT) $ 0.046120
  • msolMarinade Staked SOL (MSOL) $ 184.58
  • flokiFLOKI (FLOKI) $ 0.000050
  • usddUSDD (USDD) $ 1.00
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,567.48
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.237331
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • ghoGHO (GHO) $ 0.999997
  • doublezeroDoubleZero (2Z) $ 0.130193
  • kaiaKaia (KAIA) $ 0.076879
  • swethSwell Ethereum (SWETH) $ 3,671.46
  • iotaIOTA (IOTA) $ 0.105394
  • ethereum-name-serviceEthereum Name Service (ENS) $ 11.51
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.995919
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,722.22
  • newton-projectAB (AB) $ 0.004707
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.01
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • sbtc-2sBTC (SBTC) $ 93,070.00
  • bitcoin-svBitcoin SV (BSV) $ 20.26
  • pendlePendle (PENDLE) $ 2.43
  • usdbUSDB (USDB) $ 0.979864
  • pyth-networkPyth Network (PYTH) $ 0.068764
  • dogwifcoindogwifhat (WIF) $ 0.395951
  • sun-tokenSun Token (SUN) $ 0.020474
  • basic-attention-tokenBasic Attention (BAT) $ 0.258518
  • lorenzo-wrapped-bitcoinLorenzo Wrapped Bitcoin (ENZOBTC) $ 90,454.00
  • conflux-tokenConflux (CFX) $ 0.074655
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 92,416.00
  • the-sandboxThe Sandbox (SAND) $ 0.144936
  • justJUST (JST) $ 0.038012
  • olympusOlympus (OHM) $ 22.89
  • sad-coinSad Coin (SAD) $ 0.368234
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.144803
  • decredDecred (DCR) $ 21.57
  • sonic-3Sonic (S) $ 0.096074
  • fartcoinFartcoin (FARTCOIN) $ 0.362817
  • merlin-chainMerlin Chain (MERL) $ 0.342615
  • apenftAINFT (NFT) $ 0.00000036
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 17.67
  • flowFlow (FLOW) $ 0.218170

‘Widespread’ Crypto Exploit That Created Panic Steals Only $1K From Users

0 44

'Widespread' Crypto Exploit That Created Panic Steals Only $1K From Users

A large-scale hacking exploit targeting JavaScript code with malware that raised alarms earlier this week has managed to steal only $1,043 in cryptocurrency, according to data from Arkham Intelligence.

Cybersecurity researchers at Wiz published analysis of a “widespread” supply chain attack yesterday, writing in a blog post that bad actors used social engineering to gain control of a GitHub account belonging to Qix (Josh Junon), a developer of popular code packages for JavaScript.

The hackers published updates for some of these packages, adding malicious code that would activate APIs and crypto-wallet interfaces, as well as scan for cryptocurrency transactions in order to rewrite recipient addresses and other transaction data.

Alarmingly, Wiz’s researchers conclude that 10% of cloud environments contain some instance of the malicious code, and that 99% of all cloud environments use some of the packages targeted by the hackers responsible—but not all of these cloud environments would have downloaded the infected updates.



Despite the potential scale of the exploit, the latest data from Arkham suggests that the threat actor’s wallets have so far received the relatively modest sum of $1,043.

This has grown very incrementally in the past couple of days, encompassing transfers mostly of ERC-20 tokens, with individual transactions worth anything between $1.29 and $436.

The same exploit has also expanded beyond Qix’s npm packages, with an update yesterday from JFrog Security revealing that the DuckDB SQL database management system has been compromised.

This update also suggested that the exploit “appears to be the largest npm compromise in history,” highlighting the alarming scale and scope of the attack.

Such software supply chain attacks are becoming more common, Wiz Research researchers told Decrypt.

“Attackers have realized that compromising a single package or dependency can give them reach into thousands of environments at once,” they said. “That’s why we’ve seen a steady rise in these incidents, from typosquatting to malicious package takeovers.”

Indeed, the past few months have witnessed numerous similar incidents, including the insertion of malicious pull requests into Ethereum’s ETHcode extension in July, which garnered over 6,000 downloads.

“The npm ecosystem in particular has been a frequent target because of its popularity and the way developers rely on transitive dependencies,” said Wiz Research, whose members include the authors of Wiz’s blog on the Qix hack, Hila Ramati, Gal Benmocha and Danielle Aminov.

According to Wiz, the latest incident reinforces the need to protect the development pipeline, with organizations urged to maintain visibility across the entire software supply chain, while also monitoring for anomalous package behavior.

This seems to be what many organizations and entities were doing in the case of the Qix exploit, which was detected within two hours of publication.

Quick detection was one of the main reasons why the exploit’s financial damage remains limited, yet Wiz Research suggests there were other factors at play.

“The payload was narrowly designed to target users with specific conditions, which likely reduced its reach,” they said.

Developers are also more aware of such threats, Wiz’s researchers add, with many having protections in place to catch suspicious activity before it results in serious damage.

“It’s always possible we’ll see delayed reports of impact, but based on what we know today,” they said, “the quick detection and takedown efforts seem to have limited the attacker’s success.”

Source

Leave A Reply

Your email address will not be published.