Hackers are exploiting a JavaScript library to plant crypto drainers

cointelegraphPublicado em 2025-12-15Última atualização em 2025-12-15

Resumo

A recent surge in crypto drainer attacks is exploiting a critical vulnerability (CVE-2025-55182) in the React JavaScript library, as reported by cybersecurity nonprofit Security Alliance (SEAL). The vulnerability, which allows unauthenticated remote code execution, was disclosed on December 3 after being discovered by a white hat hacker. Attackers are using this flaw to inject wallet-draining code into legitimate crypto websites, often tricking users into signing malicious transactions through fake pop-ups or reward offers. SEAL warns that affected websites may be flagged as phishing risks and urges all site owners to immediately scan their front-end code for suspicious or obfuscated scripts, unrecognized assets, and incorrect recipient addresses in signature requests. The React team has released a patch for the vulnerability and recommends that users of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack upgrade immediately. Apps not using React Server Components or a server are not affected.

There has been a recent uptick in crypto drainers being uploaded to websites through a vulnerability in the open-source front-end JavaScript library React, according to cybersecurity nonprofit Security Alliance (SEAL).

React is used for building user interfaces, especially in web applications. The React team disclosed on Dec. 3 that a white hat hacker, Lachlan Davidson, found a security vulnerability in its software that allowed unauthenticated remote code execution, which can allow an attacker to insert and run their own code.

According to SEAL, bad actors have been using the vulnerability, CVE-2025-55182, to secretly add wallet-draining code to crypto websites.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE. All websites should review front-end code for any suspicious assets NOW,” the SEAL Team said.

“The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature.”

Wallet drainers typically dupe users into signing a transaction through methods such as a sham pop-up offering rewards or similar tactics.

Source: Security Alliance

Websites with phishing warning should check code

Affected websites may have been suddenly flagged as a possible phishing risk without explanation, according to the SEAL Team. They recommend website hosts take precautions to ensure there are no hidden drainers that could put users at risk.

“Scan host for CVE-2025-55182. Check if your front-end code is suddenly loading assets from hosts you do not recognize. Check if any of the scripts loaded by your front end code are obfuscated JavaScript. Inspect if the wallet is showing the correct recipient on the signature signing request,” they said.

Related: North Korean ‘fake Zoom’ crypto hacks now a daily threat: SEAL

“If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal,” the SEAL Team added.

React has released a fix for the vulnerability

The React team published a fix for CVE-2025-55182 on Dec. 3 and advises anyone using the react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, to upgrade immediately and close the vulnerability.

“If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability,” the team added.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Leituras Relacionadas

The Value Distribution of Stablecoins

**Summary: The Value Distribution of Stablecoins** The article argues that stablecoins are evolving from mere trading tools into broader channels for dollar access. It divides the stablecoin ecosystem into four layers to analyze how value is distributed: 1. **Issuance Layer:** Mints stablecoins, holds reserve assets, and captures the spread between reserve yield and user costs (e.g., Tether, Circle). This layer currently earns the largest profit margin. 2. **Infrastructure Layer:** Connects stablecoins to the traditional financial system, handling fiat on/off-ramps, banking integration, compliance (KYC/AML), and asset management (e.g., Bridge, BVNK). This is the "unglamorous" but critical work, building the essential bridges between crypto and real-world finance. 3. **Acquiring/Distribution Layer:** Integrates stablecoins into merchant systems, manages payment flows, and provides enterprise financial software (e.g., Stripe, Coinbase). They act as the access point for businesses. 4. **Application Layer:** The end-users and businesses that ultimately use stablecoins for payments, settlements, or as a store of value. They benefit from convenience but have little pricing power. The core thesis is that while the issuance layer currently dominates profits, the often-overlooked **infrastructure layer holds significant long-term potential**. The real challenge and barrier to mass adoption is not the on-chain transfer of stablecoins (which is simple), but the complex "last mile" integration into existing business workflows, banking systems, and regulatory frameworks across different countries. Companies in this layer are currently in a "land grab" phase, investing heavily to build networks, secure bank partnerships, and establish compliance pathways. While their position is currently pressured by the profitable issuers above and distribution platforms below, the article suggests that if stablecoins become a default financial rail for businesses, the infrastructure providers who have done the hard work of integration will ultimately gain strong pricing power and become entrenched, essential players.

marsbitHá 2h

The Value Distribution of Stablecoins

marsbitHá 2h

The Value Distribution of Stablecoins

The Value Distribution of Stablecoins The article argues that stablecoins are evolving from a mere trading tool into a broad "dollar channel." It analyzes the industry's value chain through four layers: 1. **Issuance Layer (e.g., Tether, Circle):** The top layer that mints stablecoins, holds reserve assets, and captures the thickest interest rate spread. 2. **Infrastructure Layer (e.g., Bridge, BVNK):** Connects stablecoins to the traditional financial system, handling critical but complex "dirty work" like fiat on/off-ramps, banking integration, compliance (KYC/AML), and cross-border settlement. 3. **Acquiring/Distribution Layer (e.g., Stripe, Coinbase):** Embeds stablecoins into merchant systems, manages payment flows, and integrates with enterprise software. 4. **Application Layer:** End-users and businesses that ultimately use stablecoins for payments, settlement, or storing value. The author posits that while the issuance layer currently captures the most profit, the most overlooked and potentially critical layer is infrastructure. The core challenge for stablecoin adoption isn't the on-chain transfer (which is simple), but bridging the gap between blockchain and the real-world financial system. This involves solving practical problems for businesses: fiat conversion, reconciliation, tax handling, and user onboarding. Infrastructure companies are currently in a difficult "land-grab" phase—building networks, securing banking relationships, and achieving compliance country-by-country. They face pressure from both the profitable issuance layer above and distribution platforms below. However, the author suggests this layer is building a crucial moat. Once stablecoins become a default business rail, the infrastructure players who have done the hard work of integration may gain significant, durable value and pricing power.

链捕手Há 2h

The Value Distribution of Stablecoins

链捕手Há 2h

How to Do Research Well: Deliberately Practice the Real Skills That Matter

No one truly teaches you how to do research. You're often given a desk, a pre-selected problem, and vague instructions to "create something new." Consequently, many people reverse-engineer the job based on visible outputs—papers, posts, announcements—learning only how to *appear* like a researcher rather than how to *become* one. True research capability is built from stacking small, trainable skills, nearly all of which can be developed through deliberate practice. **Pick Your Own Problem:** Most researchers absorb problems from advisors or trends, lacking the underlying reasoning. Choosing a problem you genuinely care about, as John Schulman advises, leads to original work. Develop "taste" like a muscle: predict experiment outcomes, guess paper results from methods, and track which findings remain important over time. **Upgrade Your Inputs:** Relying on shared reading lists (arXiv hot lists, filtered group chats) leads to unoriginal conclusions. Undervalued old literature often holds crucial insights (e.g., MoE, LSTM, backpropagation). Richard Sutton's "The Bitter Lesson" or Claude Shannon's 1952 talk on creative thinking are more predictive than lengthy modern surveys. Breadth matters as much as depth: draw from neuroscience, mechanism design, hardware knowledge, and honest statistics. Read papers directly, especially appendices and limitations sections. **Write Everything Down:** As Paul Graham noted, writing exposes flaws in seemingly mature ideas. Writing is the cheapest defense against self-deception. Following Feynman's principle, Darwin programmatically wrote down facts contradicting his theory to combat memory bias. Maintain a detailed log of hypotheses, setups, predictions, results, and updated understandings. Reviewing past logs fosters essential humility.

marsbitHá 4h

How to Do Research Well: Deliberately Practice the Real Skills That Matter

marsbitHá 4h

Trading

Spot
Futuros

Artigos em Destaque

O que é ATWO

I. Introdução ao ProjetoArena Two é uma plataforma interativa descentralizada que permite aos fãs desempenhar um papel ativo e tokenizado nos resultados de eventos em tempo real. Ao contrário dos modelos tradicionais de transmissão que reduzem os fãs a espectadores passivos, a Arena Two utiliza a tecnologia blockchain para permitir que os fãs votem diretamente em tempo real e influenciem os resultados em campo.II. Informação sobre o TokenNome do token: ATWO(Arena Two)III. Links RelacionadosWebsite:https://arenatwo.com/Exploradores:https://basescan.org/token/0x499D35eBE6cEe9B2Ac35Fd003fcBbeeB9CFc7B32Twitter:https://x.com/arenatwoXNota: A introdução ao projeto provém dos materiais publicados ou fornecidos pela equipa oficial do projeto, que é apenas para referência e não constitui aconselhamento de investimento. A HTX não se responsabiliza por quaisquer perdas diretas ou indiretas resultantes.

258 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

O que é ATWO

Como comprar ATWO

Bem-vindo à HTX.com!Tornámos a compra de Arena Two (ATWO) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar Arena Two (ATWO) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu Arena Two (ATWO)Depois de comprar o teu Arena Two (ATWO), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona Arena Two (ATWO)Transaciona facilmente Arena Two (ATWO) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

141 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

Como comprar ATWO

O que é ZEST

I. Introdução ao Projeto1. O que é o Zest Protocol?O Zest Protocol é um protocolo de empréstimos nativo do Bitcoin construído na camada 2 do Stacks que permite aos utilizadores ganhar rendimento com BTC ou emprestar ativos colateralizando BTC. Os contratos inteligentes do protocolo são escritos na linguagem Clarity, operam totalmente em cadeia e são de código aberto, com um design inspirado no Aave v3. O Zest é atualmente o maior protocolo DeFi no Stacks, com mais de 800 BTC depositados e um pico de TVL superior a 100 milhões de dólares. Em maio de 2026, o protocolo introduziu ainda os Cofres de Colateral em Bitcoin, estendendo as capacidades de empréstimo do Stacks para a rede principal do Bitcoin. Isso permite que os utilizadores emprestem stablecoins sem mover BTC da rede Bitcoin, possibilitando empréstimos com custódia própria.2. Como funciona o Zest Protocol?O Zest Protocol consiste em dois mercados. O mercado do Stacks é construído sobre o Aave v3, permitindo que os utilizadores depositem ativos como sBTC, STX e USDC para ganhar rendimento ou contrair empréstimos sobre-colateralizados. O LTV máximo padrão é de 50% (70% para sBTC). O mercado do Bitcoin opera através dos recém-lançados Cofres de Colateral em Bitcoin. Os utilizadores emprestam stablecoins ao bloquear BTC em cofres de custódia própria na cadeia do Bitcoin. O colateral permanece na rede principal do Bitcoin durante todo o processo, e os utilizadores mantêm a custódia, a menos que a posição seja liquidada.3. Quem fundou o Zest Protocol?Tycho Onnasch (Co-Fundador): Formado na Universidade de Oxford. Envolvido em pesquisa e subsídios para a Stacks Open Internet Foundation. Antigo Gestor na Trust Machines e Fundador da Deedmob. Perfil do LinkedIn: https://www.linkedin.com/in/tychokoonnasch/.Fernando Foy (Co-Fundador): Trabalhou anteriormente em consultoria de TI na Objectif Emploi. Perfil do LinkedIn: https://www.linkedin.com/in/fernando-foy/.Emil E. (Co-Fundador): Possui um Mestrado em Física pela Universidade de Warwick. Antigo Partner de Engenharia na Trust Machines, Desenvolvedor Full-Stack para projetos Web3 e Cientista de Dados no HSBC. Perfil do LinkedIn: https://www.linkedin.com/in/emil-e-49771a145/.Detalhes de Financiamento: Em maio de 2024, o Zest Protocol anunciou a conclusão de uma ronda de financiamento inicial de 3,5 milhões de dólares liderada por Tim Draper, com a participação da Binance Labs, Flow Traders, Trust Machines, entre outros.4. Tokenomics do $ZEST$ZEST é o token nativo do Zest Protocol com um fornecimento total fixo de 1 mil milhões de tokens e sem mecanismo inflacionário.Comunidade (27,83%): Usado para airdrops e incentivos aos utilizadores;Desenvolvimento do Ecossistema (24,82%): Usado para liquidez, parcerias, marketing, listagens em bolsas, etc.;Investidores (22,35%): Apoio às partes investidoras que apoiaram o desenvolvimento inicial do Zest Protocol;Equipa (25%): Alocado para colaboradores principais.Calendário de Vesting: Os tokens da Equipa e dos Investidores estão sujeitos a um período de bloqueio de 1 ano, seguido de 3 anos de desbloqueio linear.5. Cronologia dos Principais Marcos2022: O Zest Protocol é oficialmente fundado.Março de 2024: Concluída a auditoria de segurança e lançado o mercado de empréstimos do Stacks na rede principal.Em fevereiro de 2026, é lançado o Stacks Market V2, introduzindo Grupos de Risco.Em maio de 2026, foram introduzidos os Cofres de Colateral em Bitcoin, e um protótipo operacional da rede principal está agora disponível. Isso permite que os utilizadores utilizem BTC com custódia própria na L1 do Bitcoin como colateral para emprestar stablecoins em cadeias EVM, encerrando a necessidade de bridging, wrapping e custódia de terceiros. Este lançamento é dividido em duas fases. Fase 1: Utiliza transações pré-assinadas para restringir o movimento de BTC; Fase 2: Utiliza BitVM para verificação. II. Informações sobre o TokenNome do token: ZEST (Zest Protocol)III. Links RelacionadosWebsite: https://www.zestprotocol.com/Exploradores: https://bscscan.com/token/0x5506599c722389a60580b5213ea1da60d64754a1Twitter: https://twitter.com/ZestProtocolNota: A introdução ao projeto provém dos materiais publicados ou fornecidos pela equipa oficial do projeto, que é apenas para referência e não constitui aconselhamento de investimento. A HTX não se responsabiliza por quaisquer perdas diretas ou indiretas resultantes.

203 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.06.02

O que é ZEST

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de A (A) são apresentadas abaixo.

活动图片