Crypto Wallets Targeted In JavaScript Library Exploit—Cybersecurity Firm

bitcoinistPublicado em 2025-12-16Última atualização em 2025-12-16

Resumo

A critical vulnerability (CVE-2025-55182) in React Server Components (versions 19.0 to 19.2.0) is being actively exploited to inject malicious code into websites and steal cryptocurrency from connected wallets. The flaw, which allows unauthenticated attackers to execute arbitrary code on affected servers, has led to wallet-draining campaigns across multiple crypto sites. Cybersecurity firm Security Alliance (SEAL) warns that attackers are using the exploit to inject scripts that hijack or redirect transactions by altering user interfaces or swapping addresses. Over 50 organizations have reported compromise attempts, with scanning tools and exploit kits rapidly spreading in underground forums. Patched versions (19.0.1, 19.1.2, 19.2.1) are available, and all affected sites are urged to update immediately.

A critical flaw in React Server Components is being used by attackers to inject malicious code into live websites, and that code is siphoning crypto from connected wallets.

Reports note that the vulnerability, tracked as CVE-2025-55182, was published by the React team on December 3 and carries a maximum severity rating.

Cybersecurity firm Security Alliance (SEAL) has confirmed that multiple crypto websites are actively being targeted, and they urge operators to review all React Server Components immediately to prevent wallet-draining attacks.

Security teams say the bug allows an unauthenticated attacker to run code on affected servers, which has been turned into wallet-draining campaigns across several sites.

Image: Shutterstock

A Wide Risk To Sites Using Server Components

SEAL said the flaw affects React Server Components packages in versions 19.0 through 19.2.0, and patched releases such as 19.0.1, 19.1.2, and 19.2.1 were issued after disclosure.

The vulnerability works by exploiting unsafe deserialization in the Flight protocol, letting a single crafted HTTP request execute arbitrary code with the web server’s privileges. Security teams have warned that many sites using default configurations are at risk until they apply the updates.

Attackers Inject Wallet-Draining Scripts Into Compromised Pages

According to industry posts, threat actors are using the exploit to plant scripts that prompt users to connect Web3 wallets and then hijack or redirect transactions.

In some cases the injected code alters the user interface or swaps addresses, so a user believes they are sending funds to one account while the transaction actually pays an attacker. This method can hit users who trust familiar crypto sites and connect wallets without checking every approval.

BTCUSD now trading at $89,626. Chart: TradingView

Scanners And Proof-Of-Concepts Flooded Underground Forums

Security researchers report a rush of scanning tools, fake proof-of-concept code, and exploit kits shared in underground forums shortly after the vulnerability was disclosed.

Cloud and threat-intelligence teams have observed multiple groups scanning for vulnerable servers and testing payloads, which has accelerated active exploitation.

Some defenders say that the speed and volume of scanning have made it hard to stop all attempts before patches are applied.

More Than 50 Organizations Reported Compromise Attempts

Based on reports from incident responders, post-exploitation crypto activity has been observed at more than 50 organizations across finance, media, government, and tech.

In several investigations, attackers established footholds and then used those to deliver further malware or to seed front-end code that targets wallet users.

SEAL has emphasized that organizations failing to patch or monitor their servers could experience further attacks, and ongoing monitoring is essential until all systems are verified safe.

Featured image from Unsplash, chart from TradingView

Leituras Relacionadas

Marvell: Can't Compare to NVIDIA, Can't Meet Expectations, Overvaluation Gets Squeezed First?

Marvell Technology (MRVL.O) reported its Q2 FY2027 earnings (ending July 2026) after market close on August 27. Key points include: The company raised its full-year revenue outlook for FY2027 to $12 billion (from $11.5B) and for FY2028 to $18 billion (from $16.5B). However, these upward revisions were only slightly above market expectations and significantly trailed NVIDIA's recent explosive guidance. The Data Center segment, accounting for 79% of revenue, grew 19% quarter-over-quarter to $2.17 billion, primarily driven by connectivity products. For FY2028, management forecasts over 60% growth for this segment, again below NVIDIA's >70% outlook. A major disappointment for investors was the lack of an upward revision to the Custom ASIC business guidance, despite Marvell's recent partnership agreement with Google. The market had anticipated potential gains from Google's TPU orders, but the maintained guidance for "over 100% growth" in FY2028 (with no specific target for FY2027) led to concerns that the Google deal may be a less favorable "framework agreement" where Marvell holds a weaker negotiating position. Adjusted gross margin was flat at 58.3%. Q3 revenue guidance is $3.15 billion, slightly above consensus. Overall, the report was largely in line with expectations, but the subsequent stock decline is attributed to growth forecasts that failed to meet heightened market expectations (particularly versus NVIDIA) and lingering uncertainty around the tangible benefits of the Google ASIC partnership. High valuation faces near-term pressure, but expectations for >50% growth in the coming years and long-term ASIC opportunity may provide support.

marsbitHá 33m

Marvell: Can't Compare to NVIDIA, Can't Meet Expectations, Overvaluation Gets Squeezed First?

marsbitHá 33m

US Stock Market Trend (August 31st): Kashkari's Hawkish Remarks Weigh on Chip Stocks, US-Iran Weekend Strikes Boost Oil Prices

U.S. stock markets ended lower on Friday following hawkish remarks from Federal Reserve Chair Wash at the Jackson Hole symposium, which sharply increased the probability of a September rate hike from 35% to nearly 60%. Major indexes fell: the S&P 500 dropped 0.25%, the Nasdaq declined 0.52%, and the Dow was essentially flat. This shift in interest rate expectations pressured rate-sensitive assets, leading to significant declines in chip stocks. The Philadelphia Semiconductor Index fell 3.47%, with Nvidia dropping 4.57%, erasing about half its post-earnings gains. Geopolitical tensions also escalated over the weekend as the U.S. and Iran exchanged military strikes, raising concerns over the security of oil transit through the Strait of Hormuz. This pushed oil prices up over 2% in early Asian trading on Monday, reintroducing a geopolitical risk premium. In other energy news, former President Trump announced a landmark 25-year oil deal with Venezuela, aiming to significantly increase the country's oil production. However, this long-term supply boost was overshadowed in the short term by the Middle East conflict and the dominant market focus on interest rates. The core market narrative for the coming week revolves around the interplay between re-priced hawkish rate expectations and escalating geopolitical risks. Key areas to watch include the trajectory of Treasury yields, the evolution of U.S.-Iran tensions and its impact on oil prices, and whether the sell-off in high-valuation tech and semiconductor stocks stabilizes or continues under the pressure of higher rates.

marsbitHá 49m

US Stock Market Trend (August 31st): Kashkari's Hawkish Remarks Weigh on Chip Stocks, US-Iran Weekend Strikes Boost Oil Prices

marsbitHá 49m

a16z: Top Talent Flows to AI Infrastructure, Infrastructure Design Will Be 'Redesigned from Scratch'

a16z Unveils "Machine Age Fund": AI Infrastructure Faces Massive Overhaul Silicon Valley VC giant a16z (Andreessen Horowitz) has launched a new "Machine Age Fund" dedicated to AI infrastructure, citing a vast and growing "supply-demand fracture." Key takeaways: * **Unlimited Demand vs. Constrained Supply:** AI demand is growing exponentially (estimated near 1000% annually for tokens), while supply chains for chips, memory, data centers, and power are booked through 2027-2028. GPU prices are rising against historical trends. * **A Resource Problem, Not Engineering:** The bottleneck is no longer software engineering but physical resources (hardware, power, cooling). Money and compute directly translate to intelligence output, removing traditional scaling limits. * **Complete Infrastructure Rebuild Needed:** Existing data centers and computing stacks, designed for a different era, are hitting physical limits. Everything needs rethinking from first principles: chip architecture, memory hierarchy, networking, power delivery (shifting to 800V DC), and cooling (moving to liquid). * **Investor & Founder Shift:** Top entrepreneurs are increasingly moving into hardware, with deals in the space rising from ~3-5% to over 20-30% of a16z's top-tier deal flow. Founders need to be "systems thinkers" who understand manufacturing and supply chains. * **Massive Economic Scale:** Training a frontier model now costs $3-5B. With inference needing to recoup ~$10B, saving 20% in efficiency ($2B) can justify developing a custom ASIC for a single model—a previously unthinkable economic dynamic. * **Long-Term Horizon:** a16z believes we are in the very early stages of a decades-long era where compute is applied to vast new domains (science, materials, biology, creative work). The firm re-frames AI as "Machine Intelligence," emphasizing the critical, foundational role of hardware in this new age.

marsbitHá 1h

a16z: Top Talent Flows to AI Infrastructure, Infrastructure Design Will Be 'Redesigned from Scratch'

marsbitHá 1h

Trading

Spot
活动图片