Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more

August 18, 2026

XRP’s $2.16B long bet looks risky – But THIS could change the setup

August 18, 2026

Kraken’s parent Payward joins Anthropic’s Project Glasswing, taps Claude Mythos 5 for security

August 18, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Solana Library Supply Chain Attack Exposes Cryptocurrency Wallets
Solana Library Supply Chain Attack Exposes Cryptocurrency Wallets
Security and Privacy

Solana Library Supply Chain Attack Exposes Cryptocurrency Wallets

December 5, 20242 Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A supply chain attack on the widely used @solana/web3.js npm library, targeting private keys to steal funds, has put developers and cryptocurrency users at risk. The malicious versions, 1.95.6 and 1.95.7, were published briefly on December 2 2024, but have since been removed.

The attack exploited the library’s maintainers, likely through phishing, allowing attackers to inject malicious code. Security researchers revealed that the code exfiltrated private keys to an attacker-controlled server, sol-rpc[.]xyz, registered days before the breach.

Christophe Tafani-Dereeper, a cloud security researcher, identified the “addToQueue” backdoor function, which hijacked key-sensitive processes within the package.

The malicious activity affected projects that directly handled private keys and updated their dependencies within the five-hour attack window. These include decentralized applications (dApps) or automated bots that rely on private keys to operate.

Non-custodial wallets, which do not expose private keys during transactions, were not impacted. The stolen assets, primarily in SOL tokens, are estimated to total between $130,000 and $160,000. Major wallets like Phantom and Coinbase confirmed they were unaffected as they did not integrate the compromised versions.

Read more on threats targeting cryptocurrency assets: US Takes Down Illegal Cryptocurrency Mixing Service Samourai Wallet

Preventive Steps for Developers

Solana Labs and other experts recommended these actions for developers:

  • Audit dependencies to identify usage of @solana/web3.js versions 1.95.6 or 1.95.7

  • Update to version 1.95.8 immediately

  • Rotate keys, including multi-sigs and program authorities, if compromise is suspected

The incident highlights ongoing vulnerabilities in open-source software supply chains. This attack follows other npm package breaches, such as crypto-keccak and solana-systemprogram-utils, which similarly targeted cryptocurrency wallets.

See also  Trezor Shipping Provider Exposes 13,689 Crypto Customers to Scams

“We’ve seen a lot of different attacks on crypto this year; the ease of stealing wallets combined with the value inside the wallets is a tempting target,” said Katie Paxton-Fear, API researcher at Traceable AI.

“Combined with the rise in supply chain attacks, it perhaps was not surprising to see a threat actor combine the two with a supply chain attack targeting the wallets of Web 3.0 developers.”

The Broader Impact

Although major wallets like Phantom and Coinbase were unaffected, many developers who integrated the library into smaller dApps and tools were exposed. Security firm Socket called for increased vigilance when managing dependencies in high-risk environments.

This attack underscores the need for robust supply chain security, especially as cryptocurrency ecosystems continue to grow.

“To combat this growing threat, security programs must evolve beyond traditional CVE-based vulnerability management,” warned Spektion CEO, Joe Silva.

“A proactive approach that emphasizes understanding the risks posed by software components and their runtime behaviors will be critical for effectively managing third-party software risk and securing the software supply chain.”

Source link

Attack Chain Cryptocurrency Exposes library Solana supply wallets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more

August 18, 2026

Bitstamp deposit rule for third-party wallets over €1,000

August 17, 2026

Solana adds $378M in tokenized T-bills – Is Ethereum losing ground?

August 17, 2026

Hyperliquid’s RWA boom attracts 169K wallets – Is $60 next for HYPE?

August 17, 2026
View 2 Comments

2 Comments

  1. gluco6 reviews scam on December 6, 2024 8:14 am

    gluco6 reviews : https://gluco6reviews.usaloves.com/

    Reply
  2. gluco6 reviews on December 7, 2024 5:30 am

    gluco6 reviews : https://gluco6reviews.usaloves.com/

    Reply
Leave A Reply Cancel Reply

Top Posts

Argentina’s Presidential Candidate Sergio Massa Suggests Using Blockchain for State Finance Oversight

November 20, 2023

Elizabeth Warren highlights crypto’s role in fentanyl trade; plans to combat with bill

June 1, 2023

Mark Cuban Blasts Gary Gensler, Says SEC Chair Has Not Protected Single Crypto Investor Against Fraud

May 13, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more

August 18, 2026

XRP’s $2.16B long bet looks risky – But THIS could change the setup

August 18, 2026

Kraken’s parent Payward joins Anthropic’s Project Glasswing, taps Claude Mythos 5 for security

August 18, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,129.001.80%
  • ethereumEthereum(ETH)$1,895.660.80%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$602.200.10%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$0.99-0.10%
  • solanaSolana(SOL)$75.371.00%
  • tronTRON(TRX)$0.330900-0.10%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.010.50%
  • HyperliquidHyperliquid(HYPE)$59.172.90%