Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Massive Software Hack Puts Every Crypto Transaction at Risk

Massive Software Hack Puts Every Crypto Transaction at Risk

BeInCrypto2025/09/08 12:30
By: Mohammad Shahid
NOT-3.49%
A massive software hack threatens crypto users worldwide. Wallets may be exposed to theft. Check every transaction before signing.

A major cyberattack has shaken the global software ecosystem and placed millions of crypto users at risk. Hackers hijacked a popular developer’s account on npm, the platform that powers much of the web, and slipped malicious updates into widely used code libraries.

These libraries are buried deep inside countless apps and websites. Together, they are downloaded more than a billion times each week. That scale makes this one of the largest software supply-chain compromises ever seen.

A New Malware Targeting Crypto Transactions

The malicious code targets cryptocurrency transactions. It works in two ways.

First, if no wallet is detected, the malware looks for crypto addresses inside a website and replaces them with attacker-controlled addresses. 

It uses clever tricks to swap them for look-alikes that are visually almost identical. This makes it easy for users to miss the switch.

DO NOT USE YOUR CRYPTO WALLET unless you know for sure it is not affected by the NPM Javascript Hack. From the code I reviewed, it looks like it targets browser based wallets like metamask by intercepting the browser's methods like fetch and XMLHttpRequest. The code chooses…

— Scott Emick 🇺🇸 (@semick) September 8, 2025

Second, if a wallet like MetaMask is present, the code actively changes transactions. 

When a user prepares to send funds, the malware intercepts the data and replaces the recipient with the attacker’s address. If the user signs without carefully checking, their money is gone.

Every Crypto User Could Be At Risk

The attack began when the npm account of the developer known as Qix was compromised. Hackers then published new versions of dozens of his packages, including the core utilities mentioned above.

Developers who updated their projects pulled in these poisoned versions automatically. Any website or decentralized application that deployed them could unknowingly expose their users.

The breach was uncovered only after a build error drew attention to strange, unreadable code inside one of the updated packages. 

Security experts later found it was a sophisticated “crypto-clipper” designed to silently redirect funds.

The threat is especially serious for anyone making transactions through a web browser. If you copied an address from a site, or if you signed a transfer without checking, you could be at risk.

Ledger’s Chief Technology Officer issued a stark warning on social media.

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.The malicious payload works…

— Charles Guillemet (@P3b7_) September 8, 2025

What You Should Do Now

Experts recommend several urgent steps for all crypto holders:

  • Verify addresses: Always read the full address on your wallet’s confirmation screen or hardware device before signing.
  • Pause activity if unsure: If you use a browser-based or software wallet, consider holding off on transactions until more is known.
  • Check recent activity: Review past transfers and approvals. If you see anything suspicious, revoke approvals and move funds to a new wallet.
  • Use test transactions: When sending to a new address, transfer a small amount first to confirm it arrives safely.
  • Rely on hardware wallets: Devices that show transaction details on a separate screen remain the most secure option.

The attack shows how fragile trust in the open-source software ecosystem can be. A single compromised developer account allowed hackers to push dangerous code into billions of downloads.

This incident is still unfolding. The malicious versions are being removed, but some may remain online for days or weeks. The safest approach is vigilance.

If you use crypto, check every transaction with care. One extra look at the address on your wallet could be the difference between safety and theft.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Respect the PUMP: Crypto’s emerging meme season

Crypto is shifting into risk-on mode — pump.fun dominates meme activity, while Lido leans on treasury maneuvers

Blockworks2025/09/14 21:57
Mars Weekly | CARDS market cap surpasses $650 million, reaching a record high; probability of a 50 basis point Fed rate cut in September is 6.6%

Ethereum Foundation has released an end-to-end privacy roadmap, focusing on three main areas: privacy writing, reading, and proof, and plans to launch the experimental L2 PlasmaFold. CARDS market cap hits a record high, and pump.fun's live stream numbers have surpassed Rumble. The Shibarium cross-chain bridge suffered an attack, resulting in a loss of $2.4 million. Summary generated by Mars AI. The accuracy and completeness of this summary generated by the Mars AI model are still in the iterative update stage.

MarsBit2025/09/14 20:20

Trending news

More
1
Respect the PUMP: Crypto’s emerging meme season
2
Bittensor Hits Escape Velocity as Decentralized AI Adoption Accelerates

Crypto prices

More
Bitcoin
Bitcoin
BTC
$115,930.08
+0.03%
Ethereum
Ethereum
ETH
$4,622.47
-0.79%
XRP
XRP
XRP
$3.05
-2.39%
Tether USDt
Tether USDt
USDT
$1
+0.00%
Solana
Solana
SOL
$241.67
+0.16%
BNB
BNB
BNB
$933.63
+0.20%
USDC
USDC
USDC
$1
+0.03%
Dogecoin
Dogecoin
DOGE
$0.2799
-2.88%
TRON
TRON
TRX
$0.3490
-0.25%
Cardano
Cardano
ADA
$0.8911
-4.13%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter