• About
  • FAQ
  • Landing Page
Newsletter
Blockchain News
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Blockchain News
No Result
View All Result
Home Guide

This breach hit crypto where it hurts

admin by admin
11/24/2025
in Guide
0
This breach hit crypto where it hurts
191
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


There’s a special kind of silence that happens right before a big problem reveals itself. The “wait… that’s not supposed to be there” silence.

And you could feel this silence in crypto’s software supply chain recently.

A massive breach hit NPM, the public toolbox developers use to build half the internet – including a ton of Web3 infrastructure.

If you’ve ever used a wallet, an ENS name, or anything remotely Web3-ish, there’s a good chance some of that code came from NPM.

And this week, 400+ of those packages got infected with a malware worm called Shai Hulud.

Mom, come pick me up, I'm scared

That includes real-deal components like ENS content-hash and ensjs – the stuff that makes human-readable blockchain names actually work.

You know, the difference between sending tokens to “alex.eth” instead of “0xA93BxF…whatever.”

Every time someone downloaded one of the infected packages, Shai Hulud got to work: stealing secrets, leaking private data, and spreading into any new project it touched.

According to security firm Wiz, it was adding new victims every 30 minutes.

And shoutout to Charlie Eriksen, the researcher who caught it and hit the alarm.

Source: Charlie Eriksen

Source: Charlie Eriksen

Now, if you’re not a developer, it’s easy to shrug this off with a “well, I don’t code, so… ok? ?“

But here’s the thing: when the tools developers rely on get tampered with, everyone downstream is at risk.

Users can lose privacy, funds, or access – without ever touching a sketchy link. That’s what makes supply-chain hacks so nasty: the damage happens before the app even reaches your screen.

The good news? Open source moves fast. Once the worm was spotted, patches started rolling out, and the infected packages were removed. The fire didn’t burn the whole house down.

But the risk doesn’t disappear just because the smoke clears. This is the reminder nobody asked for: crypto isn’t only about charts, pumps, and airdrops. It’s also about trusting the math, the code, and the tools underneath it all.

So yeah… maybe peek into your digital toolbox once in a while before you start building.

Because sometimes the thing that bites you isn’t a market crash – it’s the bug hiding in your dependencies.



Source link

Related articles

Chainlink Co-Founder Sees No Big Crashes in Market Drop

Chainlink Co-Founder Sees No Big Crashes in Market Drop

02/27/2026
Ray Dalio Says CBDCs Are Coming With Major Trade-Offs

Ray Dalio Says CBDCs Are Coming With Major Trade-Offs

02/26/2026
Share76Tweet48

Related Posts

Chainlink Co-Founder Sees No Big Crashes in Market Drop

Chainlink Co-Founder Sees No Big Crashes in Market Drop

by admin
02/27/2026
0

Enjoyed this article...

Ray Dalio Says CBDCs Are Coming With Major Trade-Offs

Ray Dalio Says CBDCs Are Coming With Major Trade-Offs

by admin
02/26/2026
0

Enjoyed this article...

Sam Bankman-Fried Seeks New Trial to Challenge Conviction

Sam Bankman-Fried Seeks New Trial to Challenge Conviction

by admin
02/25/2026
0

Enjoyed this article...

LayerZero Targets 2026 Launch for Its New Zero Network

LayerZero Targets 2026 Launch for Its New Zero Network

by admin
02/24/2026
0

Enjoyed this article...

White House Talks Stall Despite a ‘Productive’ Meeting

White House Talks Stall Despite a ‘Productive’ Meeting

by admin
02/23/2026
0

Enjoyed this article...

Load More
  • Trending
  • Comments
  • Latest
BoE Opens Review on Pound-Linked Stablecoin Rules

BoE Opens Review on Pound-Linked Stablecoin Rules

11/16/2025
Jeff Bezos Returns to Lead AI Venture, Project Prometheus

Jeff Bezos Returns to Lead AI Venture, Project Prometheus

11/17/2025
AVAX Drops 6% Following $30M Token Unlock as Crypto Markets Face Stock Volatility

AVAX Drops 6% Following $30M Token Unlock as Crypto Markets Face Stock Volatility

11/17/2025

High-Speed Traders In Search of New Markets Jump Into Bitcoin

01/11/2023

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
How AI Certifications Help Professionals Stay Relevant in 2026

How AI Certifications Help Professionals Stay Relevant in 2026

03/13/2026
Anthropic’s Claude Opus 4.5 Launch Signals AI Arms Race Intensifying

Anthropic Commits $100M to Claude Partner Network for Enterprise AI Push

03/13/2026
Outset Media Index Begins Soft Launch, Introducing Standardized Media Benchmarking for Data-Driven Decisions

Outset Media Index Begins Soft Launch, Introducing Standardized Media Benchmarking for Data-Driven Decisions

03/13/2026
InfiniteInk Launches on Tezos to Give NFT Artists Full Contract Ownership

Etherlink Hits 70M Transactions as Tezos L2 Expands Developer Tools

03/12/2026
  • About
  • FAQ
  • Support Forum
  • Landing Page
  • Contact Us

© 2025 Blockchainews. All Rights Reserved

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2025 Blockchainews. All Rights Reserved