A newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets. Cybersecurity researchersA newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets. Cybersecurity researchers

Second JavaScript Exploit in Four Months Exposes Crypto Sites to Wallet Drainers

2025/12/15 21:38

A newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets.

Cybersecurity researchers have reported a surge in malicious code uploaded to legitimate websites through a vulnerability in the popular JavaScript library React — a tool used by countless crypto platforms for their front-end systems.

Crypto Drainer Attacks Surge via React Flaw

According to Security Alliance (SEAL), a nonprofit cybersecurity organization, criminals are actively exploiting a recently disclosed React vulnerability labeled CVE-2025-55182.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE,” SEAL stated on X (formerly Twitter). “All websites should review front-end code for any suspicious assets NOW.

  • HP CEO “Exposes” Ink Cartridge Vulnerability Triggering Legal Storm
  • Exness Rewards Up to $10,000 in New Bug Bounty Program
  • How to Increase Business Security Using a Honeypot

The flaw enables unauthenticated remote code execution, allowing attackers to secretly inject wallet-draining scripts into websites. The malicious code tricks users into approving fake transactions via deceptive pop-ups or reward prompts.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

SEAL cautioned that some compromised sites may be unexpectedly flagged as phishing risks. The organization advised web administrators to conduct immediate security audits to catch any injected assets or obfuscated JavaScript.

"If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal. The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature."

Phishing Flags and Hidden Drainers

The group warned that developers who find their projects mistakenly blocked as phishing pages should inspect their code first before appealing the warning.

The React development team confirmed on December 3 that it had patched the vulnerability after white hat hacker Lachlan Davidson privately reported the issue.

The fix affects the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages. The team urged all developers using these components to update immediately.

Market Opportunity
MetaDOS Logo
MetaDOS Price(SECOND)
$0.0000045
$0.0000045$0.0000045
0.00%
USD
MetaDOS (SECOND) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

AI Startup Surge Risks Repeating Tech’s Last Funding Mania

AI Startup Surge Risks Repeating Tech’s Last Funding Mania

The AI startup frenzy and FOMO are inflating round sizes and valuations. Yes, the potential is huge. But too much capital too early often leads to mediocre outcomes. Remake of 2020–22?
Share
Hackernoon2025/09/19 12:14
Bitcoin ETFs Revive with $241 Million Inflow, Ethereum ETFs Report Lowest Trading Value of the Week

Bitcoin ETFs Revive with $241 Million Inflow, Ethereum ETFs Report Lowest Trading Value of the Week

The post Bitcoin ETFs Revive with $241 Million Inflow, Ethereum ETFs Report Lowest Trading Value of the Week appeared first on Coinpedia Fintech News On September 24, the US spot Bitcoin ETF saw a combined inflow of $241.00 million, while Ethereum ETFs continued their day 3 streak of outflow. It recorded a total net outflow of $79.36 million, as per the SoSoValue report.  Bitcoin ETF Breakdown  After two consecutive days of experiencing huge sell-offs, Bitcoin ETFs finally managed to record an inflow of $241.00 million. BlackRock IBIT led with $128.90 million, and Ark and 21Shares ARKB followed with $37.72 million.  Additional gains were made by Fidelity FBTC, Bitwise BITB, and Grayscale BTC of $29.70 million, $24.69 million, and $13.56 million, respectively. VanEck HODL also made a smaller addition of $6.42 million in inflows.  Despite the inflows, the total trading value of the Bitcoin ETF dropped to $2.58 billion, with total net assets $149.74 billion. This marks 6.62% of Bitcoin market cap, slightly higher than the previous day.  Ethereum ETF Breakdown  Ethereum ETFs saw a total outflow of $79.36 million, with Fidelity’s FETH leading with $33.26 million. BlackRock ETHA also experienced heavy selling pressure of $26.47 million, followed by Grayscale’s ETHE $8.91 million. 21Shares TETH and Bitwise ETHW also posted smaller withdrawals of $6.24 million and $4.48 million, respectively.  The total trading value of Ethereum ETFs dropped below a billion, reaching $971.79 million. Net assets came in at $27.42 billion, representing 5.45% of the Ethereum market cap.  Ethereum ETF Market Context  Bitcoin is trading at $111,766, signalling a 4.6% drop compared to a week ago. Its market cap has also dipped to $2.225 trillion. Its daily trading volume has reached $49.837 billion, showing mild progress there.  Ethereum is priced at $4,011.92, with a market cap of $483.822 billion, showing a sharp decline. Its trading volume has also slipped to $37.680 billion, reflecting a slow market.  Due to heavy outflow this week, Bitcoin and Ethereum’s prices are experiencing price swings. Crypto analysts from Bloomberg warn the market to brace for further volatility.  
Share
Coinstats2025/09/25 18:40
Son of filmmaker Rob Reiner charged with homicide for death of his parents

Son of filmmaker Rob Reiner charged with homicide for death of his parents

FILE PHOTO: Rob Reiner, director of "The Princess Bride," arrives for a special 25th anniversary viewing of the film during the New York Film Festival in New York
Share
Rappler2025/12/16 09:59