Hackers are exploiting a JavaScript library to plant crypto drainers

cointelegraphPublicado em 2025-12-15Última atualização em 2025-12-15

Resumo

A recent surge in crypto drainer attacks is exploiting a critical vulnerability (CVE-2025-55182) in the React JavaScript library, as reported by cybersecurity nonprofit Security Alliance (SEAL). The vulnerability, which allows unauthenticated remote code execution, was disclosed on December 3 after being discovered by a white hat hacker. Attackers are using this flaw to inject wallet-draining code into legitimate crypto websites, often tricking users into signing malicious transactions through fake pop-ups or reward offers. SEAL warns that affected websites may be flagged as phishing risks and urges all site owners to immediately scan their front-end code for suspicious or obfuscated scripts, unrecognized assets, and incorrect recipient addresses in signature requests. The React team has released a patch for the vulnerability and recommends that users of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack upgrade immediately. Apps not using React Server Components or a server are not affected.

There has been a recent uptick in crypto drainers being uploaded to websites through a vulnerability in the open-source front-end JavaScript library React, according to cybersecurity nonprofit Security Alliance (SEAL).

React is used for building user interfaces, especially in web applications. The React team disclosed on Dec. 3 that a white hat hacker, Lachlan Davidson, found a security vulnerability in its software that allowed unauthenticated remote code execution, which can allow an attacker to insert and run their own code.

According to SEAL, bad actors have been using the vulnerability, CVE-2025-55182, to secretly add wallet-draining code to crypto websites.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE. All websites should review front-end code for any suspicious assets NOW,” the SEAL Team said.

“The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature.”

Wallet drainers typically dupe users into signing a transaction through methods such as a sham pop-up offering rewards or similar tactics.

Source: Security Alliance

Websites with phishing warning should check code

Affected websites may have been suddenly flagged as a possible phishing risk without explanation, according to the SEAL Team. They recommend website hosts take precautions to ensure there are no hidden drainers that could put users at risk.

“Scan host for CVE-2025-55182. Check if your front-end code is suddenly loading assets from hosts you do not recognize. Check if any of the scripts loaded by your front end code are obfuscated JavaScript. Inspect if the wallet is showing the correct recipient on the signature signing request,” they said.

Related: North Korean ‘fake Zoom’ crypto hacks now a daily threat: SEAL

“If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal,” the SEAL Team added.

React has released a fix for the vulnerability

The React team published a fix for CVE-2025-55182 on Dec. 3 and advises anyone using the react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, to upgrade immediately and close the vulnerability.

“If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability,” the team added.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Leituras Relacionadas

Blockchain Has Finally Started to Sail into the Mainstream After 18 Years

Blockchain Finds Its True Path After 18 Years: Becoming the Financial Backbone for AI Agents and Autonomy This analysis explores a pivotal shift in the blockchain and crypto investment landscape, driven by the dominance of AI. Major venture capital firms, including Variant, Paradigm, Haun Ventures, and YZi Labs, are moving beyond pure "crypto" investment theses. They are expanding their focus to AI, robotics, and frontier tech, signaling that blockchain is no longer seen as a standalone sector but as an underlying infrastructure layer. The core argument is that blockchain's killer application may not be user-facing apps, but rather providing the economic rails for the coming wave of AI agents, autonomous robots, and automated systems. Key capabilities like self-custody wallets, programmable stablecoins for micropayments, on-chain identity, and verifiable smart contracts are positioned as essential for a future where machines conduct economic activity. The recent $1.4 billion investment by Tether (via its venture arm) in German robotics company NEURA Robotics exemplifies this, aiming to embed Tether's wallet tools directly into robots for autonomous transactions. While many "AI + Crypto" projects remain superficial, the article concludes that true value lies where crypto is a necessary component—enabling machine-to-machine payments, agent autonomy, verifiable data provenance, and open financial settlement for the AI era. For crypto venture capital, this convergence with AI represents both an adaptation to shifting capital flows and a potential path to unlocking the large-scale, non-speculative utility the industry has long sought.

marsbitHá 7m

Blockchain Has Finally Started to Sail into the Mainstream After 18 Years

marsbitHá 7m

Blockchain has finally begun sailing toward the main channel after 18 years

After 18 years of development, blockchain technology is beginning to move from a specialized niche into mainstream adoption, according to a recent industry analysis. The shift is reflected in the changing strategies of major crypto venture capital firms, which are expanding their focus beyond pure "digital ownership" towards broader themes like "autonomy." The report highlights that leading VC firms like Variant, Paradigm, Haun Ventures, and YZi Labs are broadening their investment mandates to include not only crypto but also artificial intelligence (AI), robotics, biotech, and other frontier technologies. This reflects a recognition that the isolated "crypto investment" narrative is losing appeal to limited partners (LPs) as capital and attention increasingly flow toward AI and other high-growth tech sectors. A key emerging thesis is that blockchain's most significant future application may not be as a consumer-facing product, but as the underlying economic and settlement infrastructure for the AI era. As AI agents and autonomous systems become more prevalent, they will require programmable, global, and low-cost payment networks (like stablecoins), verifiable digital identities, and secure wallets to manage transactions and assets on behalf of users. The investment by stablecoin issuer Tether into robotics company NEURA, with plans to integrate its wallet technology, is cited as a prime example of this convergence. However, the article cautions that simply labeling projects as "AI + Crypto" is insufficient. True value lies in integrations where blockchain technology is essential—such as enabling machine-to-machine micropayments, verifiable data provenance for AI, or transparent governance for autonomous organizations—rather than being a superficial marketing add-on. In conclusion, while AI currently dominates the tech narrative and capital flows, it may ultimately create the real-world, high-frequency demand that the crypto industry has long sought. For crypto VCs and projects, the path forward is to position blockchain not as a competing sector, but as a critical foundational layer powering autonomy and economic activity in an AI-driven future.

链捕手Há 13m

Blockchain has finally begun sailing toward the main channel after 18 years

链捕手Há 13m

Y Combinator Co-founder: How to Make a Billion Dollars?

The Y Combinator co-founder argues that becoming a billionaire by founding a successful startup is not only possible but demonstrably achievable without unfair or unethical practices. He disputes a politician's claim to the contrary, using the example of a founder whose company grew at 93% monthly solely through creating a product users loved and recommended. The core mechanism is exponential growth. A conservative 15% monthly growth rate compounds to a 4384x increase over five years, which can easily lead to billion-dollar valuations and founder wealth. The process depends on two key variables: the growth rate and the duration it can be sustained. A high growth rate stems from a great product that users naturally promote, while a long duration requires a large enough market. For aspiring founders, especially young ones, the simplest path is to build something they and their friends genuinely need. Young people's current needs often predict future mass-market trends. He advises against actively "searching" for ideas, as this tends to filter out unconventional but promising ones. Instead, inspiration should come from working on interesting projects with friends, as many iconic companies (e.g., Apple, Facebook) started this way. Ultimately, building a massively valuable startup is not about exploitation but empathy: deeply understanding a user group and building a product that significantly improves their lives. This, powered by exponential growth in a large market, is the legitimate path to immense wealth creation.

Foresight NewsHá 16m

Y Combinator Co-founder: How to Make a Billion Dollars?

Foresight NewsHá 16m

The 800V Voltage Standard Championed by Nvidia: Which Infrastructure Providers Stand to Benefit?

NVIDIA is actively promoting the 800VDC architecture as a key direction for its next-generation AI factories and high-power racks, particularly for the upcoming Rubin and Kyber platforms. The primary driver is the rapidly increasing power density of AI racks, with designs like GB200/GB300 NVL72 reaching 120-140kW and future systems potentially hitting 180-220kW. At such high power levels, traditional low-voltage power delivery becomes inefficient due to massive current, leading to significant copper use, cable bulk, heat, and power loss. The 800VDC standard aims to increase efficiency by transmitting power at higher voltage and lower current to the rack before stepping it down locally for GPUs. NVIDIA claims this can improve efficiency by up to 5%, reduce total cost of ownership (TCO) by up to 30%, and cut copper usage by approximately 45%. This shift redefines infrastructure roles, pushing power engineering to the forefront alongside GPU performance. Key beneficiaries and ecosystem partners highlighted include: 1. **Power Infrastructure Providers:** Companies like Vertiv, Schneider Electric, Delta Electronics (台达电), and Korean firms LS Electric and HD Hyundai Electric are involved in designing next-gen AI factory power distribution, rack power supplies, and backup systems. 2. **Power Semiconductors:** Suppliers of SiC/GaN devices, such as Infineon and STMicroelectronics, are better suited for high-voltage, high-efficiency conversion in this new architecture. 3. **Connectivity & Structure:** The focus shifts to high-reliability components like busbars, high-voltage connectors, and advanced PCBs that meet stricter insulation and safety requirements. 4. **Liquid Cooling & Rack ODM:** As power and heat density rise, liquid cooling becomes critical. Full-rack system integrators (e.g., Dell, Wiwynn, Wistron) must now demonstrate robust pre-delivery testing capabilities, including burn-in testing under full load, requiring significant power and cooling infrastructure in their factories. The transition is not immediate for all data centers but is targeted at high-density AI factories. NVIDIA’s 800VDC ecosystem is in a preparatory phase, with full-scale production expected to align with the 2027 launch of Kyber rack-scale systems. The investment thesis revolves around which companies can demonstrate proven product integration, customer validation, and reliable delivery of complete, high-power AI rack systems, making power, cooling, and testing capabilities new critical variables in the AI infrastructure value chain alongside GPUs.

marsbitHá 36m

The 800V Voltage Standard Championed by Nvidia: Which Infrastructure Providers Stand to Benefit?

marsbitHá 36m

Did 'Unlimited Minting' Actually Happen? Zcash Founder Responds to Four Major Market Concerns

The Orchard shielding pool in the privacy cryptocurrency Zcash was recently found to have contained a critical counterfeiting vulnerability that existed for four years. This discovery caused significant market panic and a sharp drop in the price of ZEC, though it has since recovered partially. Zcash founder Zooko Wilcox addressed four key questions raised by the vulnerability. First, while it's unknown if the bug was exploited, he believes it likely was not, citing advanced, targeted discovery methods, a rapid response to freeze the pool, and the typical "smash-and-grab" nature of past crypto exploits. Second, he states that if no exploitation occurred, all legitimate user funds in Orchard are recoverable. However, cautious users moving funds should be aware of privacy trade-offs and other risks involved in transferring to transparent or Sapling pools. Third, users currently cannot independently verify that the total ZEC supply hasn't been inflated due to this bug. However, the proposed "Ironwood" network upgrade will restore this ability by permanently sealing the Orchard pool. This will prevent any counterfeit funds from circulating and allow anyone running a node to cryptographically verify that the supply cap has not been breached. Finally, regarding other undiscovered vulnerabilities, Wilcox notes that intensive ongoing audits by multiple teams, including using advanced AI-assisted tools, have so far found no other counterfeiting bugs. This provides increased, though not absolute, confidence. In conclusion, while assessments suggest the bug was likely unused and funds are safe, the core issue was the loss of user-verifiable supply integrity. The Ironwood upgrade is presented as the solution, aiming to restore trust by allowing users to independently verify Zcash's supply security without relying on third-party assurances.

marsbitHá 37m

Did 'Unlimited Minting' Actually Happen? Zcash Founder Responds to Four Major Market Concerns

marsbitHá 37m

Trading

Spot
Futuros

Artigos em Destaque

Como comprar BILL

Bem-vindo à HTX.com!Tornámos a compra de Billions Network (BILL) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Billions Network (BILL) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Billions Network (BILL)Depois de comprar o teu Billions Network (BILL), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Billions Network (BILL)Transaciona facilmente Billions Network (BILL) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

289 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar BILL

O que é ATWO

I. Introdução ao ProjetoArena Two é uma plataforma interativa descentralizada que permite aos fãs desempenhar um papel ativo e tokenizado nos resultados de eventos em tempo real. Ao contrário dos modelos tradicionais de transmissão que reduzem os fãs a espectadores passivos, a Arena Two utiliza a tecnologia blockchain para permitir que os fãs votem diretamente em tempo real e influenciem os resultados em campo.II. Informação sobre o TokenNome do token: ATWO(Arena Two)III. Links RelacionadosWebsite:https://arenatwo.com/Exploradores:https://basescan.org/token/0x499D35eBE6cEe9B2Ac35Fd003fcBbeeB9CFc7B32Twitter:https://x.com/arenatwoXNota: A introdução ao projeto provém dos materiais publicados ou fornecidos pela equipa oficial do projeto, que é apenas para referência e não constitui aconselhamento de investimento. A HTX não se responsabiliza por quaisquer perdas diretas ou indiretas resultantes.

258 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

O que é ATWO

Como comprar ATWO

Bem-vindo à HTX.com!Tornámos a compra de Arena Two (ATWO) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Arena Two (ATWO) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Arena Two (ATWO)Depois de comprar o teu Arena Two (ATWO), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Arena Two (ATWO)Transaciona facilmente Arena Two (ATWO) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

141 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar ATWO

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de A (A) são apresentadas abaixo.

活动图片