MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Huge malware attack targeting crypto exposes DeFi’s Achilles heel
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$72,165.004.04%
  • ethereumEthereum(ETH)$2,116.955.75%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$651.051.70%
  • rippleXRP(XRP)$1.423.24%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$90.563.91%
  • tronTRON(TRX)$0.2843230.42%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.99%
  • dogecoinDogecoin(DOGE)$0.0960026.52%
Blockchain Technology

Huge malware attack targeting crypto exposes DeFi’s Achilles heel

Last updated: September 9, 2025 9:55 pm
Published: 6 months ago
Share

DeFi is reeling from a supply chain attack that targeted crypto wallets.

On Monday it was revealed that hackers have poisoned JavaScript packages with crypto-stealing malware. Those packages were collectively downloaded more than 2.6 billion times last week, potentially threatening millions of users worldwide.

Now, DeFi protocols and wallet providers are scrambling to reassure users that they’re not at risk.

The incident highlights how much of DeFi’s $204 billion ecosystem is vulnerable to an unexpected point of failure — an Achilles heel, if you will.

It comes as cybercriminals have stolen $2.2 billion from crypto protocols this year, a 77% uptick from the total amount stolen throughout 2024, according to DefiLlama.

Blockchain developers go to great lengths to ensure their networks are truly decentralised and distributed. After all, much of the value of blockchain technology comes from its resilience to single points of failure that are the bane of more centralised systems.

Yet the years of honing decentralised systems were made largely irrelevant when the developer who maintains over a dozen popular JavaScript packages, which most of DeFi relies on, fell victim to a phishing hack.

To be sure, the compromises didn’t cause any critical failures. But it certainly gave users a scare and slowed things down temporarily.

The hackers updated the JavaScript packages after taking control, injecting malicious code able to hijack network traffic. The goal was to wait for users to send crypto transactions and then use the code to redirect funds to the hacker’s wallet, according to an analysis by Aikido Security.

It’s similar to how North Korean hackers targeted Bybit in February, stealing $1.4 billion from the crypto exchange.

Like the Bybit hack, the malicious code only impacts individuals accessing the compromised applications over the web. So as long as users don’t send any transactions until they get the all clear from DeFi protocols and wallet providers, they’re not at risk.

Despite the hack being potentially the largest supply chain attack in history, the attackers have only stolen a minimal amount so far.

An Ethereum address believed to belong to the hackers has only received around $500 worth of crypto so far, according to Arkham Intelligence.

“The biggest financial impact of this entire incident will be the collective thousands of hours spent by engineering and security teams around the world working to clean compromised environments,” Security Alliance, a crypto security nonprofit, said in a blog post.

Still, it’s a stark reminder that the game theory and decentralisation that blockchain developers value so highly can all be for naught if there are other points of failure outside of their purview.

VOTE: ENS votes to adopt Security Alliance’s Safe Harbor Agreement

PROPOSAL: Gauntlet proposes to renew its partnership with Compound for another year

VOTE: Lisk DAO votes to deploy LSK to Base and deploy liquidity to Aerodrome using Arrakis

Crypto Twitter is upset to find out that half of Coinbase’s code is written using AI — something they see as a potential security risk.

The exchange was recently subject to an incident that saw hackers compromise almost 70,000 users’ data.

Read more on DL News

This news is powered by DL News DL News

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Free Crypto Games and Crypto Earning Games: How Toshi.bet Stands Out in 2025 – Novo Momento
Pantera, Blockchange lead funding for privacy-focused Zama Confidential Blockchain Protocol at $1 billion valuation
ZachXBT Exposes $2-Million Coinbase Impersonation Scam Onchain Clues
Morgan Stanley Seeks to Reshape Crypto Investing with Staking-ETF Proposal
Top 3 Layer-2 Cryptos Poised to Transform the Future of Finance

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article XION launches Apple ID login for blockchain, dropping wallets and seed phrases
Next Article Easily earn $8,888 a day,Dogecoin users successfully transitioned to artificial intelligence (Doge cloud mining) and doubled their monthly income
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d