Hackers are exploiting a JavaScript library to plant crypto drainers

cointelegraphPublished on 2025-12-15Last updated on 2025-12-15

Abstract

A recent surge in crypto drainer attacks is exploiting a critical vulnerability (CVE-2025-55182) in the React JavaScript library, as reported by cybersecurity nonprofit Security Alliance (SEAL). The vulnerability, which allows unauthenticated remote code execution, was disclosed on December 3 after being discovered by a white hat hacker. Attackers are using this flaw to inject wallet-draining code into legitimate crypto websites, often tricking users into signing malicious transactions through fake pop-ups or reward offers. SEAL warns that affected websites may be flagged as phishing risks and urges all site owners to immediately scan their front-end code for suspicious or obfuscated scripts, unrecognized assets, and incorrect recipient addresses in signature requests. The React team has released a patch for the vulnerability and recommends that users of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack upgrade immediately. Apps not using React Server Components or a server are not affected.

There has been a recent uptick in crypto drainers being uploaded to websites through a vulnerability in the open-source front-end JavaScript library React, according to cybersecurity nonprofit Security Alliance (SEAL).

React is used for building user interfaces, especially in web applications. The React team disclosed on Dec. 3 that a white hat hacker, Lachlan Davidson, found a security vulnerability in its software that allowed unauthenticated remote code execution, which can allow an attacker to insert and run their own code.

According to SEAL, bad actors have been using the vulnerability, CVE-2025-55182, to secretly add wallet-draining code to crypto websites.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE. All websites should review front-end code for any suspicious assets NOW,” the SEAL Team said.

“The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature.”

Wallet drainers typically dupe users into signing a transaction through methods such as a sham pop-up offering rewards or similar tactics.

Source: Security Alliance

Websites with phishing warning should check code

Affected websites may have been suddenly flagged as a possible phishing risk without explanation, according to the SEAL Team. They recommend website hosts take precautions to ensure there are no hidden drainers that could put users at risk.

“Scan host for CVE-2025-55182. Check if your front-end code is suddenly loading assets from hosts you do not recognize. Check if any of the scripts loaded by your front end code are obfuscated JavaScript. Inspect if the wallet is showing the correct recipient on the signature signing request,” they said.

Related: North Korean ‘fake Zoom’ crypto hacks now a daily threat: SEAL

“If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal,” the SEAL Team added.

React has released a fix for the vulnerability

The React team published a fix for CVE-2025-55182 on Dec. 3 and advises anyone using the react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, to upgrade immediately and close the vulnerability.

“If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability,” the team added.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Related Reads

MY Group Completes Web4.0 First Stock Listing Layout, SEC Officially Discloses Form 8-K Announcement

MY Group has completed the listing layout for the "Web4.0 First Share," with the U.S. Securities and Exchange Commission (SEC) formally disclosing a Form 8-K report. According to the filing, the company's board has officially appointed Mr. Zhang Dingwen as Chief Executive Officer (CEO) and Executive Director, marking a significant upgrade in management and the entry into a new phase of its global capital market strategy. The disclosure of Form 8-K, used for reporting major corporate events, coincides with market information indicating the company is advancing several key capital market initiatives. These include a global brand system upgrade, corporate strategic restructuring, and a change of its stock ticker symbol. These moves are viewed by industry experts as signals of accelerated internationalization and enhanced global market presence. Concurrently, MY Group's proposed "Web4.0 Ecosystem" is garnering market attention. The company is integrating core capabilities across social traffic portals, global payment systems, public blockchain infrastructure, digital asset trading, and AI-powered financial systems. Analysts suggest that by closing this ecosystem loop, MY Group has the potential to become a next-generation platform merging Web2 user scale with Web3 asset frameworks and AI financial capabilities. With the management upgrade finalized, the global brand strategy launched, and the stock ticker change pending, MY Group is positioning itself as a focal point in the global technology capital market as a potential leading Web4.0 platform enterprise.

marsbit9h ago

MY Group Completes Web4.0 First Stock Listing Layout, SEC Officially Discloses Form 8-K Announcement

marsbit9h ago

Trading

Spot
Futures

Hot Articles

What is GENIUS

I. Project Introduction1. What Is Genius?Genius (GENIUS) is positioned as the “ultimate on-chain terminal,” a decentralized trading platform focused on privacy and speed. By integrating top-tier privacy technology, it aims to build a next-generation privacy trading infrastructure across networks such as BNB Chain, enabling users to interact on-chain with a seamless experience comparable to centralized exchanges.2. How Does Genius Work?Genius's core technical architecture is structured as follows:(1) Chain-invisible: Users do not need to manually handle multi-step approvals for cross-chain operations, asset wrapping, or complex gas management.(2) Signatureless Trading: Through integrations such as Turnkey, Genius enables instant trading without pop-up confirmations or per-transaction authorization.(3) Aggregator of Aggregators: Genius is powered by a best-in-class aggregation stack integrated with more than 150 DEXs, claiming superior quote efficiency compared with competing products.(4) Account Management: The platform adopts a non-custodial architecture and leverages Turnkey and Lit Protocol for key management, allowing users to securely access their accounts through passkeys.3. Who Created Genius?According to its official Terms of Service, Genius was developed by Shuttle Labs, Inc. Based on the project’s official X account, Ryan Myher is one of the key contributors driving product iteration, including developments such as the rollout of the Ghost protocol, as well as broader community engagement.Binance founder CZ has officially joined the project as an advisor, with the goal of helping the team build a faster and more privacy-preserving on-chain trading experience.In addition, the project has received strong backing from YZi Labs, which has invested in Genius and works alongside the Genius Foundation, responsible for maintaining the core Genius Bridge Protocol (GBP).4. Genius TokenomicsGENIUS is the native token of the Genius ecosystem. As of now, the project has not released a full tokenomics document.Based on the latest official disclosures, Genius incorporates a deflationary mechanism, and 4.6% of the total token supply had already been burned during the early launch phase.Genius Points (GP) System:(1) Trade-to-Earn: The platform has established a reward pool of 200 million Genius Points, and users earn GP for every trade executed through the terminal.(2) Tiering and Badges: Genius features a progression-based badge system ranging from Smart to God, with higher levels unlocking additional perks and benefits.(3) Native Yield: Users holding designated assets such as usdGG in the dashboard can earn native yield directly without going through complex staking.(4) Referral Incentives: Referrers can earn fee rebates of over 45% paid in USDC, along with additional GP.5. Timeline & Key MilestonesMarch 2020: The project’s official X account was created, marking the beginning of its early preparation phase.January 13, 2026: Genius announced a multi-million-dollar investment from YZi Labs and simultaneously confirmed CZ as an advisor to accelerate the buildout of its privacy trading infrastructure.April 18, 2026: The project announced that the Ghost privacy protocol would be launching soon.April 29, 2026: The Ghost protocol officially opened to its first 50 testers, marking the beginning of a new era for privacy trading on BNB Chain. At the same time, the team confirmed 4.6% of tokens have been burnt.​II. Token Information1) Basic InformationToken name: GENIUS (Genius)III. Related LinksWebsite:https://www.tradegenius.com/homeExplorers:https://bscscan.com/address/0x1f12b85aac097e43aa1555b2881e98a51090e9a6Socials:https://x.com/GeniusTerminalNote: The project introduction comes from the materials published or provided by the official project team, which is for reference only and does not constitute investment advice. HTX does not take responsibility for any resulting direct or indirect losses.

1.2k Total ViewsPublished 2026.04.29Updated 2026.05.11

What is GENIUS

How to Buy GENIUS

Welcome to HTX.com! We've made purchasing Genius (GENIUS) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Genius (GENIUS) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Genius (GENIUS)After purchasing your Genius (GENIUS), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Genius (GENIUS)Easily trade Genius (GENIUS) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

2.4k Total ViewsPublished 2026.04.29Updated 2026.05.11

How to Buy GENIUS

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of A (A) are presented below.

活动图片