CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: ‘Widespread’ Crypto Exploit That Created Panic Steals Only $1K From Users
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > ‘Widespread’ Crypto Exploit That Created Panic Steals Only $1K From Users
News

‘Widespread’ Crypto Exploit That Created Panic Steals Only $1K From Users

CoinRSS
Last updated: September 11, 2025 9:18 am
CoinRSS Published September 11, 2025
Share

A large-scale hacking exploit targeting JavaScript code with malware that raised alarms earlier this week has managed to steal only $1,043 in cryptocurrency, according to data from Arkham Intelligence.

Cybersecurity researchers at Wiz published analysis of a “widespread” supply chain attack yesterday, writing in a blog post that bad actors used social engineering to gain control of a GitHub account belonging to Qix (Josh Junon), a developer of popular code packages for JavaScript.

The hackers published updates for some of these packages, adding malicious code that would activate APIs and crypto-wallet interfaces, as well as scan for cryptocurrency transactions in order to rewrite recipient addresses and other transaction data.

Alarmingly, Wiz’s researchers conclude that 10% of cloud environments contain some instance of the malicious code, and that 99% of all cloud environments use some of the packages targeted by the hackers responsible—but not all of these cloud environments would have downloaded the infected updates.

Despite the potential scale of the exploit, the latest data from Arkham suggests that the threat actor’s wallets have so far received the relatively modest sum of $1,043.

This has grown very incrementally in the past couple of days, encompassing transfers mostly of ERC-20 tokens, with individual transactions worth anything between $1.29 and $436.

The same exploit has also expanded beyond Qix’s npm packages, with an update yesterday from JFrog Security revealing that the DuckDB SQL database management system has been compromised.

This update also suggested that the exploit “appears to be the largest npm compromise in history,” highlighting the alarming scale and scope of the attack.

Such software supply chain attacks are becoming more common, Wiz Research researchers told Decrypt.

“Attackers have realized that compromising a single package or dependency can give them reach into thousands of environments at once,” they said. “That’s why we’ve seen a steady rise in these incidents, from typosquatting to malicious package takeovers.”

Indeed, the past few months have witnessed numerous similar incidents, including the insertion of malicious pull requests into Ethereum’s ETHcode extension in July, which garnered over 6,000 downloads.

“The npm ecosystem in particular has been a frequent target because of its popularity and the way developers rely on transitive dependencies,” said Wiz Research, whose members include the authors of Wiz’s blog on the Qix hack, Hila Ramati, Gal Benmocha and Danielle Aminov.

According to Wiz, the latest incident reinforces the need to protect the development pipeline, with organizations urged to maintain visibility across the entire software supply chain, while also monitoring for anomalous package behavior.

This seems to be what many organizations and entities were doing in the case of the Qix exploit, which was detected within two hours of publication.

Quick detection was one of the main reasons why the exploit’s financial damage remains limited, yet Wiz Research suggests there were other factors at play.

“The payload was narrowly designed to target users with specific conditions, which likely reduced its reach,” they said.

Developers are also more aware of such threats, Wiz’s researchers add, with many having protections in place to catch suspicious activity before it results in serious damage.

“It’s always possible we’ll see delayed reports of impact, but based on what we know today,” they said, “the quick detection and takedown efforts seem to have limited the attacker’s success.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

FTX Will Hand Out Over $5 Billion in Bankruptcy Repayments This Month

$6mln bet on Hyperliquid – Will HYPE move to $40 or fall back?

This Week in Crypto Games: $250K Pokémon Card Auction, ‘Pixels’ $4M Competition, ‘Nifty Island’ Token Date

Dogecoin, XRP and Solana Slide as Bitcoin Price Falls Below $97K

Crypto, Stock Trading Platform eToro Soars to $5.4 Billion Market Cap After Nasdaq Debut

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Kaito crypto – Here’s how it could avoid a $1.09 pullback
Next Article Avalanche clears key hurdle after 8 rejections: Can AVAX reach $32?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
US Trustee Calls Out ‘Dishonest Debtor’ in $12.5M Crypto Bankruptcy Case
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?