Crypto Wallets Targeted In JavaScript Library Exploit—Cybersecurity Firm

bitcoinistPubblicato 2025-12-16Pubblicato ultima volta 2025-12-16

Introduzione

A critical vulnerability (CVE-2025-55182) in React Server Components (versions 19.0 to 19.2.0) is being actively exploited to inject malicious code into websites and steal cryptocurrency from connected wallets. The flaw, which allows unauthenticated attackers to execute arbitrary code on affected servers, has led to wallet-draining campaigns across multiple crypto sites. Cybersecurity firm Security Alliance (SEAL) warns that attackers are using the exploit to inject scripts that hijack or redirect transactions by altering user interfaces or swapping addresses. Over 50 organizations have reported compromise attempts, with scanning tools and exploit kits rapidly spreading in underground forums. Patched versions (19.0.1, 19.1.2, 19.2.1) are available, and all affected sites are urged to update immediately.

A critical flaw in React Server Components is being used by attackers to inject malicious code into live websites, and that code is siphoning crypto from connected wallets.

Reports note that the vulnerability, tracked as CVE-2025-55182, was published by the React team on December 3 and carries a maximum severity rating.

Cybersecurity firm Security Alliance (SEAL) has confirmed that multiple crypto websites are actively being targeted, and they urge operators to review all React Server Components immediately to prevent wallet-draining attacks.

Security teams say the bug allows an unauthenticated attacker to run code on affected servers, which has been turned into wallet-draining campaigns across several sites.

Image: Shutterstock

A Wide Risk To Sites Using Server Components

SEAL said the flaw affects React Server Components packages in versions 19.0 through 19.2.0, and patched releases such as 19.0.1, 19.1.2, and 19.2.1 were issued after disclosure.

The vulnerability works by exploiting unsafe deserialization in the Flight protocol, letting a single crafted HTTP request execute arbitrary code with the web server’s privileges. Security teams have warned that many sites using default configurations are at risk until they apply the updates.

Attackers Inject Wallet-Draining Scripts Into Compromised Pages

According to industry posts, threat actors are using the exploit to plant scripts that prompt users to connect Web3 wallets and then hijack or redirect transactions.

In some cases the injected code alters the user interface or swaps addresses, so a user believes they are sending funds to one account while the transaction actually pays an attacker. This method can hit users who trust familiar crypto sites and connect wallets without checking every approval.

BTCUSD now trading at $89,626. Chart: TradingView

Scanners And Proof-Of-Concepts Flooded Underground Forums

Security researchers report a rush of scanning tools, fake proof-of-concept code, and exploit kits shared in underground forums shortly after the vulnerability was disclosed.

Cloud and threat-intelligence teams have observed multiple groups scanning for vulnerable servers and testing payloads, which has accelerated active exploitation.

Some defenders say that the speed and volume of scanning have made it hard to stop all attempts before patches are applied.

More Than 50 Organizations Reported Compromise Attempts

Based on reports from incident responders, post-exploitation crypto activity has been observed at more than 50 organizations across finance, media, government, and tech.

In several investigations, attackers established footholds and then used those to deliver further malware or to seed front-end code that targets wallet users.

SEAL has emphasized that organizations failing to patch or monitor their servers could experience further attacks, and ongoing monitoring is essential until all systems are verified safe.

Featured image from Unsplash, chart from TradingView

Letture associate

a16z: Top Talent Flows to AI Infrastructure, Infrastructure Design Will Be 'Redesigned from Scratch'

a16z Unveils "Machine Age Fund": AI Infrastructure Faces Massive Overhaul Silicon Valley VC giant a16z (Andreessen Horowitz) has launched a new "Machine Age Fund" dedicated to AI infrastructure, citing a vast and growing "supply-demand fracture." Key takeaways: * **Unlimited Demand vs. Constrained Supply:** AI demand is growing exponentially (estimated near 1000% annually for tokens), while supply chains for chips, memory, data centers, and power are booked through 2027-2028. GPU prices are rising against historical trends. * **A Resource Problem, Not Engineering:** The bottleneck is no longer software engineering but physical resources (hardware, power, cooling). Money and compute directly translate to intelligence output, removing traditional scaling limits. * **Complete Infrastructure Rebuild Needed:** Existing data centers and computing stacks, designed for a different era, are hitting physical limits. Everything needs rethinking from first principles: chip architecture, memory hierarchy, networking, power delivery (shifting to 800V DC), and cooling (moving to liquid). * **Investor & Founder Shift:** Top entrepreneurs are increasingly moving into hardware, with deals in the space rising from ~3-5% to over 20-30% of a16z's top-tier deal flow. Founders need to be "systems thinkers" who understand manufacturing and supply chains. * **Massive Economic Scale:** Training a frontier model now costs $3-5B. With inference needing to recoup ~$10B, saving 20% in efficiency ($2B) can justify developing a custom ASIC for a single model—a previously unthinkable economic dynamic. * **Long-Term Horizon:** a16z believes we are in the very early stages of a decades-long era where compute is applied to vast new domains (science, materials, biology, creative work). The firm re-frames AI as "Machine Intelligence," emphasizing the critical, foundational role of hardware in this new age.

marsbit29 min fa

a16z: Top Talent Flows to AI Infrastructure, Infrastructure Design Will Be 'Redesigned from Scratch'

marsbit29 min fa

Claude's Safety Mechanism Backfires Spectacularly, AI Deletes Developer's 700GB Home Directory in a Fit of Rage

Claude's safety mechanisms backfired spectacularly, leading an AI to delete a developer's entire 700GB home directory. The developer, Guillemot, asked Claude Fable 5 to write a script to create isolated sandbox folders in /tmp for AI agents and clean them up afterward, ensuring files in use wouldn't be deleted. Because the task involved risky delete operations, Claude's built-in safety system triggered an "adversarial review," automatically downgrading the model from the capable Fable 5 to the more conservative Opus 5, and then to Opus 4.8, to perform a security check. The Opus 4.8 model successfully tested the script, correctly identifying the /tmp and home directories as off-limits for deletion. However, during the cleanup phase that followed the test, it reused a variable name from the testing phase. This variable contained the path to the user's home directory. Consequently, the model executed a delete command on that exact path it had just deemed unsafe, wiping out 700GB of data. The intended /tmp directory remained untouched. The incident highlights critical flaws in Anthropic's safety downgrade system, which community developers have criticized for being overly sensitive, reducing model capability for complex tasks, and being "sticky" for an entire session once triggered. The irony is that a mechanism designed to hand off dangerous tasks to a safer, more conservative model instead delegated it to a weaker model that made a catastrophic error in variable scope and path handling.

marsbit50 min fa

Claude's Safety Mechanism Backfires Spectacularly, AI Deletes Developer's 700GB Home Directory in a Fit of Rage

marsbit50 min fa

Starting from Anthropic, Dissecting the Hyperliquid Perpetual Contract Sector

The article explores the emergence of pre-IPO perpetual synthetic asset markets on Hyperliquid's HIP-3 protocol, focusing on platforms like Ventuals, Trade.xyz, and Entropy. It begins with the intense secondary market demand for Anthropic stock, as illustrated by Jesse Leimgruber's experience. The HIP-3 protocol allows anyone to launch a perpetual DEX by locking $40M, with 30% of Hyperliquid's volume flowing through it. The piece details the rise and fall of Ventuals, the first major platform for trading pre-IPO synthetics like Anthropic and SpaceX. Its failure was due to extreme funding rates (reportedly hitting 8,700% annualized for Anthropic) and a pricing model vulnerable to thin liquidity, leading to a 45% crash in a SpaceX contract. Trade.xyz succeeded by using a simple 30-minute internal TWAP for pricing and dominates HIP-3 volume. Entropy, backed by a $14M Ribbit Capital-led round, attempts to improve on Ventuals by capping funding rates and using a hybrid oracle that blends its order book with private market valuations, while pricing Anthropic by total market cap. However, it struggles with accurately pricing private companies like Anthropic, unlike public stocks like SanDisk (SNDK) where arbitrage bots align prices. The article concludes by noting a potential Kraken testnet deployment on HIP-3, suggesting regulated entities may adopt its technology within permissioned frameworks. The evolution of these platforms highlights the challenges and iterative progress in creating decentralized markets for private company exposure.

marsbit1 h fa

Starting from Anthropic, Dissecting the Hyperliquid Perpetual Contract Sector

marsbit1 h fa

Trading

Spot
活动图片