Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Malicious packages for dYdX cryptocurrency exchange empties user wallets
    Cryptocurrency

    Malicious packages for dYdX cryptocurrency exchange empties user wallets

    February 6, 20262 Mins Read


    Open source packages published on the npm and PyPI repositories were laced with code that stole wallet credentials from dYdX developers and backend systems and, in some cases, backdoored devices, researchers said.

    “Every application using the compromised npm versions is at risk ….” the researchers, from security firm Socket, said Friday. “Direct impact includes complete wallet compromise and irreversible cryptocurrency theft. The attack scope includes all applications depending on the compromised versions and both developers testing with real credentials and production end-users.”

    Packages that were infected were:

    npm (@dydxprotocol/v4-client-js):

    • 3.4.1
    • 1.22.1
    • 1.15.2
    • 1.0.31

    PyPI (dydx-v4-client):

    Perpetual trading, perpetual targeting

    dYdX is a decentralized derivatives exchange that supports hundreds of markets for “perpetual trading,” or the use of cryptocurrency to bet that the value of a derivative future will rise or fall. Socket said dYdX has processed over $1.5 trillion in trading volume over its lifetime, with an average trading volume of $200 million to $540 million and roughly $175 million in open interest. The exchange provides code libraries that allow third-party apps for trading bots, automated strategies, or backend services, all of which handle mnemonics or private keys for signing.

    The npm malware embedded a malicious function in the legitimate package. When a seed phrase that underpins wallet security was processed, the function exfiltrated it, along with a fingerprint of the device running the app. The fingerprint allowed the threat actor to correlate stolen credentials to track victims across multiple compromises. The domain receiving the seed was dydx[.]priceoracle[.]site, which mimics the legitimate dYdX service at dydx[.]xyz through typosquatting.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    As crypto industry expands, U.S. slashes office examining dirty money safeguards of cryptocurrency exchanges

    Cryptocurrency

    Cryptocurrency Fuels Human Trafficking, Child Abuse, and Online Scams, Report Finds

    Cryptocurrency

    Police arrest three for cryptocurrency fraud

    Cryptocurrency

    Court acquits defendants in cryptocurrency mining case

    Cryptocurrency

    Top 5 Cloud Mining Platforms for Cryptocurrency in 2026 – Why HashBitcoin Stands Out

    Cryptocurrency

    Better Cryptocurrency to Buy Now and Hold for 10 Years: XRP vs. Bitcoin

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Property

    l’Inde passe des quartiers d’affaires commerciaux aux quartiers d’affaires mondiaux

    Precious Metal

    Why Precious Metals Are a Smart Investment in 2025

    Stock Market

    Top Dividend Stocks (April 2025)

    Editors Picks

    It’s going to smack people upside of their earholes

    January 27, 2026

    B2B fintech Yaspa on using its ‘homegrown rebrand’ to break America

    October 15, 2025

    Investors pivot to active management and global opportunities

    October 11, 2025

    Avec Nickel, on peut créer un compte en Espagne, sans besoin du NIE

    April 6, 2025
    What's Hot

    Un ancien analyste poursuit Freepoint Commodities, alléguant avoir subi des pressions pour faciliter des délits d’initiés

    May 28, 2025

    Navigating the Fintech Regulatory Landscape

    August 28, 2024

    Job opening marks new era in agriculture: Operators for autonomous tractors fleets

    August 14, 2024
    Our Picks

    Green Street fait l’acquisition de l’Australian Property Journal afin d’étendre la présence mondiale de Green Street News

    March 12, 2025

    La start-up brestoise Chloé in the sky lève 1,2 million d’euros

    April 29, 2025

    Twisted Metal season 2 adds Saylor Bell Curda, Michael James Shaw, and Lisa Gilroy to the cast

    August 29, 2024
    Weekly Top

    Fintech Sandbox Announces Global Startups Headlining Demo Day 12

    February 17, 2026

    Wolfden Highlights Potential Precious Metal Upside at Canoe Landing

    February 17, 2026

    Goldman Sachs Is Raising Price Targets 10%+ on 4 Blue Chip Dividend Stocks

    February 17, 2026
    Editor's Pick

    Wyoming Aims to Launch US Dollar-Backed Stablecoin in 2025

    August 24, 2024

    Happy Dancing Turtle and Hunt Utilities Group host Aug. 8 open house – Brainerd Dispatch

    July 27, 2024

    PLDT cherche à acquérir la participation de KKR dans la filiale Maya Fintech -Le 27 février 2025 à 18:49

    February 27, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.