3 crypto attacks in 24 hours – From fake apps to a $14.2M SOL theft

ambcryptoPublished on 2026-07-12Last updated on 2026-07-12

Abstract

The cryptocurrency space witnessed a high volume of attacks within 24 hours, highlighting several major security threats. First, fraudsters targeted SecondFi by creating fake browser extensions and apps to steal crypto; the company clarified its official channels and warned against unsolicited links. In a separate incident, a compromised early Solana whale wallet led to the theft of 180,900 SOL (worth $14.2 million), with the stolen funds being bridged to Ethereum and laundered via Tornado Cash. Finally, the jscrambler npm package suffered a supply chain attack where stolen credentials were used to publish malicious versions containing an information-stealing payload. These events underscore the prevalence of phishing, wallet exploits, and software supply chain vulnerabilities, emphasizing the need for vigilance, verifying official sources, and prompt software updates.

Crypto scams are becoming increasingly prevalent, drawing widespread attention. In fact, more than three breaches occurred in the past 24 hours, with a few notable cases highlighted below.

SecondFi falls victim to a scam

Fraudsters impersonated SecondFi by developing phony browser extensions and applications that were intended to steal cryptocurrency or access users’ wallets.

To address the confusion, SecondFi clarified,

There is no new application or link, it is the same.

The team asserted that it will never ask users to download software, click links, sign transactions, or transfer assets through direct messages or emails.

Therefore, to prevent phishing scams and money theft, the team advised users to only install the official Chrome extension that has the blue verified checkmark and to access SecondFi via its official website.

Source: SecondFi/X

How did a theft result in a loss of 180,900 SOL?

In the second case, blockchain investigator ZachXBT claims that an early Solana [SOL] whale wallet was compromised. This resulted in the purported theft of 180,900 SOL, worth $14.2 million.

According to on-chain data, the wallet initially displayed unusual unstaking activity, indicating that the attacker took over the staked assets before transferring them to newly made Solana addresses to combine and exchange the money.

Later, the stolen assets were bridged from Solana to Ethereum [ETH] to obscure transaction trails and access greater liquidity. Moreover, the investigation asserted that some money had already been transferred using Tornado Cash, making them far harder to trace.

A sophisticated supply chain attack

Finally, jscrambler npm package became the target of a software supply chain attack after an attacker allegedly stole the login credentials needed to release new versions. For context, an information-stealing (infostealer) payload was included in malicious releases 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.

Source: Socket/X

These releases were made to run malicious code on Linux, macOS, or Windows systems. Initially, a preinstall script that executes automatically during npm install was used to distribute the malware.

But in versions 8.18.0 and 8.20.0, the attacker incorporated the malicious code straight into the package, evading security measures such as npm install –ignore-scripts, which typically stops preinstall scripts from executing.

According to jscrambler, the attack was made possible by compromised npm publishing credentials, which allowed for unapproved releases. Following that, developers were urged to update immediately to version 8.22.0, which contains the fix.


Final Summary

  • Different hacking techniques like phishing scams, wallet compromises, and software supply chains are raising alarms.
  • By avoiding unsolicited links, updating compromised software, and confirming official sources, users, and developers can stay safe.

Trending Cryptos

Related Questions

QWhat type of attack did SecondFi warn its users about, and what specific advice was given to avoid it?

ASecondFi warned users about a phishing scam involving fake browser extensions and apps designed to steal cryptocurrency or access wallets. The team advised users to only install the official Chrome extension with a blue verified checkmark and to access the platform via its official website to prevent theft.

QAccording to the article, how did the attacker try to obscure the trail of the stolen 180,900 SOL tokens?

AThe attacker bridged the stolen SOL tokens from the Solana blockchain to the Ethereum blockchain. Additionally, some of the funds were transferred using the privacy mixer Tornado Cash, making them far harder to trace.

QWhat was the malicious component in the compromised jscrambler npm package versions, and how did it evolve?

AThe malicious component was an information-stealing (infostealer) payload. Initially, it was distributed via a 'preinstall' script that runs automatically during 'npm install'. In later versions (8.18.0, 8.20.0), the attacker embedded the malicious code directly into the package to evade security measures that block preinstall scripts.

QWhat common root cause enabled the unauthorized releases in the jscrambler supply chain attack?

AThe attack was made possible by compromised npm publishing credentials, which allowed the attacker to make unauthorized releases of the package.

QWhat are the three general categories of crypto attacks highlighted in the article's final summary?

AThe final summary highlights three categories of attacks: phishing scams, wallet compromises, and software supply chain attacks.

Related Reads

StarkWare tests quantum-resistant Bitcoin transaction on mainnet

StarkWare researcher Avihu Levy has conducted the first test of an experimental quantum-resistant transaction on the Bitcoin mainnet. The transaction was confirmed in block 964,199, spending an output protected by Levy's Quantum Safe Bitcoin (QSB) scheme, which was mined by MARA Pool. QSB combines hash-based one-time signatures with computational searches to bind authorization to a specific transaction, aiming to prevent forgery even if a quantum computer breaks Bitcoin's current elliptic-curve cryptography. This test demonstrates that Bitcoin's existing rules can support this form of quantum-resistant spending without a protocol change. However, the method remains costly and impractical for regular use. Generating the test transaction required hours of GPU computation, costing an estimated $150 to $200. Levy and StarkWare position QSB as a last-resort safety net, not a replacement for future protocol-level upgrades. Currently, QSB transactions are nonstandard under Bitcoin Core's policies, requiring direct submission to mining services like MARA's Slipstream for confirmation. The development comes amid concerns that future quantum computers could theoretically derive Bitcoin private keys minutes after a public key is exposed. While QSB offers a transaction-level solution, StarkWare's CEO emphasized the need for a broader soft fork for network-wide protection. Bitcoin developers are separately evaluating proposals, such as BIP-360, to introduce quantum-resistant features at the protocol level.

cointelegraph8m ago

StarkWare tests quantum-resistant Bitcoin transaction on mainnet

cointelegraph8m ago

Accumulation Across the Entire Market, BTC May Challenge the $86,000 Resistance Zone?

Record-breaking short liquidations ignited a roughly 26% rebound in Bitcoin from the August lows. Unlike previous leverage-driven squeezes, this rally is supported by substantial buy-side demand. U.S. spot ETFs recorded their strongest weekly inflows of the year, with $2.23 billion, while bitcoin continued to flow out of exchanges. On-chain data shows all wallet cohorts are simultaneously accumulating coins, confirming broad-based buying. Leverage has been effectively cleared post-squeeze, with bitcoin-denominated futures open interest contracting. The funding rate has hovered around neutral, indicating the move was driven more by short covering than new speculative longs. A key challenge lies ahead: a significant supply wall in the $81k to $86k range. This zone is defined by the cost basis of long-term holders, concentrated sell-side order book liquidity, and pending short liquidation clusters. Market structure appears top-heavy, with large-cap assets outperforming smaller ones, a pattern typical of early-cycle rallies. Bitcoin has also decoupled from equities during this move. Cycle indicators have risen from a prolonged "cool" phase, positioning the market in an early stage, far from historical top readings. The path forward hinges on whether this overhead supply can be absorbed. A sustained close above ~$83.3k with continued ETF inflows would signal strength. Conversely, a break below the ~$70k short-term holder cost basis, and ultimately the ~$62k-$65k support floor, would indicate weakening momentum.

marsbit42m ago

Accumulation Across the Entire Market, BTC May Challenge the $86,000 Resistance Zone?

marsbit42m ago

When Real Estate Ownership Goes Digital: What Happens to Your Rights, Risks, and Liquidity?

"Tokenizing Real Estate: Rights, Risks, and the Path to Liquidity" While tokenizing real-world assets (RWA) gains traction, real estate presents unique complexities. Beyond technical token issuance, critical challenges remain: enforcing legal rights, managing the underlying physical asset, and creating genuine secondary market liquidity. This article explores these issues through OneAsset, a Dubai-based commercial real estate (CRE) tokenization platform. OneAsset moves away from simply offering asset fragmentation. Instead, it focuses on institutional-grade infrastructure, prioritizing asset quality, legal enforceability, and operational fundamentals. Each property is held in an independent, single-asset vault, backed by a legally separate Special Purpose Vehicle (SPV) for bankruptcy remoteness. Investors acquire tokens representing the economic rights to a specific property, with precise legal claims defined by the underlying SPV structure. OneAsset emphasizes that tokenization cannot transform a poor-quality asset. Its initial focus is on institutional investors and quality Dubai-based CRE, selected for stable tenant cash flows and a clear regulatory environment. The platform integrates compliance by design, aiming to embed investor qualification and transfer rules directly into the token architecture. A core insight is that asset fragmentation does not automatically create liquidity. True liquidity depends on the asset's inherent quality—its location, cash flow, and valuation—as well as sufficient buyer demand. The goal is not just tradability, but making real estate rights more easily priced, verified, and reallocated. Looking ahead, the article discusses the potential for "AiFi" (AI-powered finance). For AI agents to autonomously allocate capital, investment assets like real estate tokens must become truly "machine-readable." This requires a high degree of standardization in legal rights, valuations, cash flows, and compliance data—a direction OneAsset is pursuing through its structured data reporting. In conclusion, real estate tokenization is shifting from a technology narrative to a focus on asset fundamentals. Blockchain can enhance efficiency and programmability, but it cannot replace sound underwriting, property management, or legal execution. The real work begins after the asset is on-chain.

marsbit1h ago

When Real Estate Ownership Goes Digital: What Happens to Your Rights, Risks, and Liquidity?

marsbit1h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of SOL (SOL) are presented below.

活动图片