Crypto Wallets Targeted In JavaScript Library Exploit—Cybersecurity Firm

bitcoinistPubblicato 2025-12-16Pubblicato ultima volta 2025-12-16

Introduzione

A critical vulnerability (CVE-2025-55182) in React Server Components (versions 19.0 to 19.2.0) is being actively exploited to inject malicious code into websites and steal cryptocurrency from connected wallets. The flaw, which allows unauthenticated attackers to execute arbitrary code on affected servers, has led to wallet-draining campaigns across multiple crypto sites. Cybersecurity firm Security Alliance (SEAL) warns that attackers are using the exploit to inject scripts that hijack or redirect transactions by altering user interfaces or swapping addresses. Over 50 organizations have reported compromise attempts, with scanning tools and exploit kits rapidly spreading in underground forums. Patched versions (19.0.1, 19.1.2, 19.2.1) are available, and all affected sites are urged to update immediately.

A critical flaw in React Server Components is being used by attackers to inject malicious code into live websites, and that code is siphoning crypto from connected wallets.

Reports note that the vulnerability, tracked as CVE-2025-55182, was published by the React team on December 3 and carries a maximum severity rating.

Cybersecurity firm Security Alliance (SEAL) has confirmed that multiple crypto websites are actively being targeted, and they urge operators to review all React Server Components immediately to prevent wallet-draining attacks.

Security teams say the bug allows an unauthenticated attacker to run code on affected servers, which has been turned into wallet-draining campaigns across several sites.

Image: Shutterstock

A Wide Risk To Sites Using Server Components

SEAL said the flaw affects React Server Components packages in versions 19.0 through 19.2.0, and patched releases such as 19.0.1, 19.1.2, and 19.2.1 were issued after disclosure.

The vulnerability works by exploiting unsafe deserialization in the Flight protocol, letting a single crafted HTTP request execute arbitrary code with the web server’s privileges. Security teams have warned that many sites using default configurations are at risk until they apply the updates.

Attackers Inject Wallet-Draining Scripts Into Compromised Pages

According to industry posts, threat actors are using the exploit to plant scripts that prompt users to connect Web3 wallets and then hijack or redirect transactions.

In some cases the injected code alters the user interface or swaps addresses, so a user believes they are sending funds to one account while the transaction actually pays an attacker. This method can hit users who trust familiar crypto sites and connect wallets without checking every approval.

BTCUSD now trading at $89,626. Chart: TradingView

Scanners And Proof-Of-Concepts Flooded Underground Forums

Security researchers report a rush of scanning tools, fake proof-of-concept code, and exploit kits shared in underground forums shortly after the vulnerability was disclosed.

Cloud and threat-intelligence teams have observed multiple groups scanning for vulnerable servers and testing payloads, which has accelerated active exploitation.

Some defenders say that the speed and volume of scanning have made it hard to stop all attempts before patches are applied.

More Than 50 Organizations Reported Compromise Attempts

Based on reports from incident responders, post-exploitation crypto activity has been observed at more than 50 organizations across finance, media, government, and tech.

In several investigations, attackers established footholds and then used those to deliver further malware or to seed front-end code that targets wallet users.

SEAL has emphasized that organizations failing to patch or monitor their servers could experience further attacks, and ongoing monitoring is essential until all systems are verified safe.

Featured image from Unsplash, chart from TradingView

Letture associate

Weekly On-Chain Data Review: Robinhood Chain Explodes, FWA Goes Viral, Mantle Doubles Down on RWA

**Chain Data Weekly Digest: Vault Regulation, Robinhood Memecoin Surge, and FWA's NFT Gamble** * **Vault Managers Face SEC Scrutiny:** SEC Commissioner Hester Peirce warned that some DeFi Vault strategies could trigger investment advisor regulations. This may lead to licensing requirements, potentially sidelining smaller managers while bringing more traditional finance firms on-chain. The industry debates whether Vaults are purely code-driven or resemble discretionary portfolio management. * **Robinhood Chain's Memecoin-Led Boom:** Despite its initial RWA focus, Robinhood Chain has seen explosive early growth driven by memecoin trading and launchpads, which now dominate its DEX volume. The chain facilitates memecoin trading via tokenized stock pairs. It boasts over $800M in on-chain assets, $5B in stablecoin market cap, and strong fee revenue, positioning it as a consumer trading hub. * **FWA Revives NFT Activity with a Gamble:** The Fake World Assets (FWA) protocol, a gachapon-style system on Ethereum where users pay to randomly win deposited NFTs, has rapidly captured 10% of Ethereum's mainnet gas consumption in its first week. It demonstrates how simple, consumer-facing mechanics can reignite NFT engagement, attracting a broad user base. * **CEX Consolidation & DEX Growth:** The closures of BitMEX and BitMart highlight intense central exchange (CEX) competition and consolidation. Meanwhile, the DEX/CEX spot trading volume ratio hit a record high of 24.3% in July, signaling a shift of trading activity and innovation to on-chain venues. * **Mantle's RWA Focus at 3 Years:** Celebrating its third anniversary, Mantle Network is solidifying its role as a "full-stack distribution layer" for tokenized real-world assets (RWA). It ended Q2 with $1.2B in DeFi TVL, $955M in stablecoin market cap, and a growing suite of native RWA trading infrastructure like Fluxion and xChange.

marsbit10 min fa

Weekly On-Chain Data Review: Robinhood Chain Explodes, FWA Goes Viral, Mantle Doubles Down on RWA

marsbit10 min fa

From 'Western Learning Ants' to Korean Pension Funds: Why Does Korean Capital Continue to Flow to the US?

Summary: "From 'Western Ants' to National Pension: Why Korean Capital Continues to Flow to the U.S.?" South Korea’s capital is increasingly moving toward U.S. markets, driven by two key investor groups. Individual retail investors, known as "Western Ants," actively trade U.S. stocks overnight, seeking exposure to major tech firms and higher returns often unavailable in Korea’s concentrated domestic market. Simultaneously, the National Pension Service (NPS), managing over $1.16 trillion in assets, is expanding its global investment footprint. Facing demographic pressures and the sheer size of its fund, NPS has steadily increased overseas allocations, with over half its financial assets now invested abroad. A recent memorandum of understanding with six top U.S. venture capital firms (including Sequoia and a16z) marks a strategic extension into Silicon Valley’s private investment ecosystem, aiming to access growth-stage tech opportunities while leveraging external managers’ expertise. While both flows reflect limitations of Korea’s home market, their risk profiles differ sharply: retail investors often pursue speculative, concentrated bets, whereas NPS must ensure long-term, diversified returns for national retirement security. This outward shift also creates macroeconomic tensions, as demand for dollars from both groups pressures the Korean won, prompting coordinated measures between NPS and the central bank to mitigate currency volatility. Ultimately, Korea’s growing financial integration with global markets—especially the U.S.—signals a broader structural shift where citizens’ wealth and pension sustainability are increasingly tied to worldwide economic dynamics.

marsbit21 min fa

From 'Western Learning Ants' to Korean Pension Funds: Why Does Korean Capital Continue to Flow to the US?

marsbit21 min fa

This Strategy Earned Hefei One Trillion Yuan

This article analyzes the "Hefei Model" that enabled a municipal state-owned investment to generate paper profits exceeding one trillion yuan through the 2026 IPO of ChangXin Memory Technologies (CXMT). It argues against framing this success as a "lucky gamble," instead presenting it as the result of a deliberate institutional system designed to enable long-term industrial investment. The system comprises three core components. First, a **quantified risk-tolerance mechanism**, including a 40% loss allowance for venture funds and a clear "duty-fulfilled exemption" list, decouples project failure from personal career risk for decision-makers, allowing them to focus on industrial potential rather than personal liability. Second, **strategic investment in critical supply chain gaps**: Hefei doesn't just invest in "good" projects, but targets "missing" links essential for its key industries (appliances, displays, cars). The investment in CXMT aimed to fill the critical DRAM memory chip gap, subsequently attracting over 450 upstream and downstream firms and creating a full semiconductor cluster. Third, **institutional authorization for counter-cyclical investment**: Protected by the risk-tolerance framework, Hefei supported CXMT with increased investment during the 2023 global memory industry downturn, enabling it to scale production and capitalize on the 2025 AI-driven demand surge. The article concludes that the true lesson is not the specific investment but building the institutional infrastructure—quantified risk tolerance, deep industry chain analysis, and counter-cyclical mandates—that makes such long-term, strategic bets possible. It notes the final challenge is perfecting the exit mechanism to complete the investment cycle and transform paper gains into sustainable fiscal returns and reinvestment capacity.

marsbit35 min fa

This Strategy Earned Hefei One Trillion Yuan

marsbit35 min fa

Trading

Spot
活动图片