Logo Logo
  • All News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market
  • Blockchain
  • AI
  • More
    • About Us
    • Contact
Reading: Crypto’s Biggest NPM Attack in History Steals Under $50: SEAL Security Analysis
Share
The Crypto BluntThe Crypto Blunt
Font ResizerAa
  • Home
  • Read History
  • Technology
  • Login
  • Blog
  • Contact
Search
  • Pages
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • Read History
  • Personalized
    • Read History
  • Personalized
    • Read History
  • Categories
    • Technology
  • Categories
    • Technology
  • Categories
    • Technology
Have an existing account? Sign In
Follow US
  • Pages
  • Pages
  • Pages
  • Personalized
  • Personalized
  • Personalized
  • Categories
  • Categories
  • Categories

Home - News - Crypto’s Biggest NPM Attack in History Steals Under $50: SEAL Security Analysis

News

Crypto’s Biggest NPM Attack in History Steals Under $50: SEAL Security Analysis

Hardy Zad
Last updated: September 9, 2025 10:42 am
Hardy Zad
Published: September 9, 2025
Share
Crypto's Biggest NPM Attack in History Steals Under $50

The node package manager (NPM) account of a prominent software developer was breached by hackers, who then injected malware into widely used JavaScript libraries, aiming at crypto wallets.

Contents
  • Small-Scale Crypto Theft: ETH and Memecoins Among Stolen Funds
  • Are Crypto Projects that Didn’t Download NPMs Still at Risk?
  • Ledger and MetaMask Among Crypto Apps Unaffected by NPM Attack
  • “You Won’t Be Instantly Drained,” Crypto Founder Says: A Look at the NPM Attack

A total of $50 worth of crypto was stolen by hackers in a massive supply chain hack that affected JavaScript software libraries, according to industry security researchers.

According to findings shared on Monday by the crypto intelligence platform Security Alliance, hackers broke into a well-known software developer’s node package manager (NPM) account and added malware to popular JavaScript libraries that have already been downloaded over 1 billion times, potentially putting countless crypto projects at risk. Ethereum and Solana wallets were specifically targeted, Security Alliance said.

Fortunately, less than $50 has been stolen from the crypto space so far, according to the security firm, which identified the Ethereum wallet address “0xFc4a48” as what it believes to be the only malicious address so far. It also added on X:

”Picture this: you compromise the account of a NPM developer whose packages are downloaded more than 2 billion times per week. You could have unfettered access to millions of developer workstations. Untold riches await you. The world is your oyster. You profit less than 50 USD.”

“The hacker didn’t fully capitalize on the amount of access they had. It’s like finding the keycard to Fort Knox and using it as a bookmark. The malware was widespread but at this point is nearly completely neutralized,” pseudonymous SEAL security researcher Samczsun.

The $50 figure was, however, raised from five cents a few hours earlier, suggesting the potential damage may still be unfolding.

Small-Scale Crypto Theft: ETH and Memecoins Among Stolen Funds

Five cents were stolen in Ether, while another $20 worth of a memecoin was compromised, according to Security Alliance.

Etherscan data shows that the malicious address has received Brett (BRETT), Andy (ANDY), Dork Lord (DORK), Ethervista (VISTA), and Gondola (GONDOLA) memecoins so far.

Are Crypto Projects that Didn’t Download NPMs Still at Risk?

The breach targeted packages such as chalk, strip-ansi, and color-convert — small utilities buried deep in the dependency trees in countless projects. Even developers who never installed them directly could have been exposed.

NPM is like an app store for developers — a central library where they share and download small code packages to build JavaScript projects.

The attackers appear to have planted a crypto-clipper, a type of malware that silently replaces wallet addresses during transactions to divert funds.

Ledger chief technology officer Charles Guillemet was among many who have urged crypto users to proceed with caution when confirming onchain transactions.

Ledger and MetaMask Among Crypto Apps Unaffected by NPM Attack

Crypto wallet providers Ledger and MetaMask marked their platforms as safe from the NPM attack, pointing to “multiple layers of defense” to protect against such attacks.

The team behind Phantom Wallet said it does not use any vulnerable versions of the affected packages, while Uniswap noted that none of its apps are at risk.

Aerodrome, Blast, Blockstream Jade, and Revoke.cash were among the other crypto platforms that said they were unaffected by the supply chain attack.

“You Won’t Be Instantly Drained,” Crypto Founder Says: A Look at the NPM Attack

Only crypto projects that updated after the malware-infected NPM package was published may be at risk, according to 0xngmi, the pseudonymous founder of crypto analytics platform DefiLlama. Even then, users must approve the malicious transaction for it to work.

Though like Guillemet, he said it may be safer to avoid using crypto websites until developers behind those platforms clean up the bad packages.

TAGGED:BlockchainCryptocryptocurrencyFraud

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
ByHardy Zad
Follow:
Hardy Zad is our in house crypto researcher and writer, delving into the stories which matter from crypto and blockchain markets being used in the real world.
Previous Article Crypto Market Shift: Ethereum Volatility Drops to Zero, Bitcoin Oversold Creates Uptrend, XRP Shows Recovery Signs Crypto Market Shift: Ethereum Volatility Drops to Zero, Bitcoin Oversold Creates Uptrend, XRP Shows Recovery Signs
Next Article Korea as Web3 Testbed: Factblock CEO Credits Crypto Culture and Advanced Technology Korea as Web3 Testbed: Factblock CEO Credits Crypto Culture and Advanced Technology
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
RSS FeedFollow
The Crypto BluntLogo
Subscribe to our newsletter to get our newest articles instantly!
Most Read
Stablecoin Turmoil Could Disrupt ECB Policy, Dutch Central Bank Chief Warns

Stablecoin Turmoil Could Disrupt ECB Policy, Dutch Central Bank Chief Warns

What is GateToken?

What is GateToken (GT)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethereum? 

What is Ethereum (ETH)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethereum Classic?

What is Ethereum Classic (ETC)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethena?

What is Ethena (ENA)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Ethena USDe?

What is Ethena USDe? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Dogecoin?

What is Dogecoin(DOGE)? What It Is, Overview, Works, Guides, Everything You Need to Know

what is Dai

What is Dai (DAI)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Chainlink?

What is Chainlink (LINK)? What It Is, Overview, Works, Guides, Everything You Need to Know

What is Cronos?

What is Cronos(CRO)? What It Is, Overview, Works, Guides, Everything You Need to Know

thecryptoblunt-telegram
Logo

The most recent real-time news about crypto at The Crypto Blunt. Latest trusted news about bitcoin, ethereum, blockchain, mining, cryptocurrency prices and more.

NEWS
  • Explained
  • News
  • AI
  • Blockchain
COMPANY
  • About Us
  • Career
GET IN TOUCH
  • Contact
  • Disclaimer
  • Privacy Policy
  • Cookie Policy

© The Crypto Blunt 2025. All Rights Reserved.

© The Crypto Blunt. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?