Bài đăng

Hiển thị các bài đăng có nhãn compromised

Solana dev library web3.js compromised to steal private keys

Solana’s web3.js library was compromised yesterday in a supply chain attack that installed malicious packages capable of stealing the private keys of users and draining their funds.   The attack was reported by Solana developer @trentdotsol and specifically affected versions 1.95.6 and 1.95.7 of the Solana web3.js library. Since then, a wave of Solana-based developers have come out to confirm they are not impacted by the exploit. Unaffected firms include Solflare, Phantom Wallet, and Helium.  Solana’s web3.js is a JavaScript library accessible to developers wanting to build Solana-based apps. Reports suggest that maintainers of the library may have been targeted by a phishing campaign as attackers gained access to the “publish-access account.” anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected) if you ...

Code4arena X account compromised, used for Paradigm endorsed phishing scam

A smart contract security marketplace Code4arena appears to be the latest victim of a SIM swap attack on X. An X account for Code4 arena , a smart contract auditing platform, was compromised allowing a hacker to publish a scam post luring people to believe an airdrop was endorsed by a venture capital firm. In an X post that appeared on Nov. 27, 2023 the hacker published a post announcing an airdrop of ARENA tokens endorsed by Paradigm, a San Francisco-based crypto venture capital investment firm. Code4Arena twitter got hacked Do not click any links pic.twitter.com/yIoRGascQt — Defenders Dao (@defendersdao) November 28, 2023 The scale of the hack is not immediately clear as no public statements from Code4arena have been made so far. According to external reports, however, the incident was the result of a SIM-swap attack. At the time of writing, the post is deleted, but crypto.news was able to independently verify the authenticity of the original post. You might als...