Breaking
December 5, 2024

Phantom Safe from Solana Web3.js Bug; Upgrade to 1.95.8 Urged Hassan Shittu | usagoldmines.com

Phantom, a prominent wallet provider in the Solana ecosystem, has reassured its users that it is unaffected by a critical vulnerability recently discovered in the Solana/web3.js library.

The exploit, found in versions 1.95.6 and 1.95.7, involved malicious code designed to steal private keys. This flaw severely threatened applications and developers relying on the compromised versions, potentially exposing user funds to theft.

Phantom’s security team confirmed in a statement on X that the wallet provider has never used these versions in its infrastructure, ensuring its users remain safe.

The vulnerability has sent ripples through the Solana developer community.

Solana developer Trent Sol, who first sounded the alarm, described the compromised versions as a “secret stealer” capable of leaking private keys through seemingly legitimate CloudFlare headers.

He urged developers and projects to immediately upgrade to version 1.95.8 or roll back to unaffected version 1.95.5.

Despite these vulnerabilities, major projects such as Drift, Solflare, and Phantom confirmed their immunity, either due to avoiding the impacted versions or deploying additional security layers.

The Bug in Solana Web3.js Library: Who Is Affected?

According to a Socket.dev post, a supply chain attack compromised the Solana/web3.js library, a core component for developers building on Solana.

This type of attack, targeting dependencies widely used by developers, inserted a backdoor function named addToQueue into versions 1.95.6 and 1.95.7.

The malicious function enabled the exfiltration of private keys by disguising its activity as legitimate CloudFlare header data.

Once captured, these keys were transmitted to a hardcoded Solana wallet address identified as FnvLGtucz4E1ppJHRTev6Qv4X7g8Pw6WPStHCcbAKbfx.

Cybersecurity researchers, including Christophe Tafani-Dereeper from Datadog, analyzed the malicious versions and highlighted the sophisticated nature of the exploit.

They discovered that the domain used for the operation (sol-rpc[.]xyz) had been registered on November 22, just days before the attack became public.

The domain was hosted behind CloudFlare, with the command-and-control (C2) server now offline.

This timeline points to a carefully planned attack, likely due to a phishing or social engineering campaign targeting the library’s maintainers.

The npm package manager, which hosts Solana/web3.js, swiftly removed the compromised versions.

Developers using the affected versions were advised to update version 1.95.8 immediately or audit their projects for suspicious dependencies.

Broader Implications for Solana and Web3 Security

The Solana ecosystem has responded rapidly to mitigate the fallout.

In addition to Phantom, major projects like Backpack have assured their users that the exploit does not affect them.

Supply chain attacks like this have become increasingly common as malicious actors target the tools and libraries developers rely on.

Earlier this year, a similar attack involved a malicious Python package named “Solana-py,” which masqueraded as a legitimate API to steal wallet keys.

Similarly, in October this year, the Checkmarx threat research team uncovered a new malware campaign on the Python Package Index (PyPI) repository, targeting cryptocurrency users through a malicious package named “CryptoAITools.”

The malware masquerades itself as a legitimate cryptocurrency trading tool and uses a deceptive graphical user interface to distract victims while executing malicious activities on Windows and macOS systems.

Once installed, the malware launches a sophisticated multi-stage infection process, downloading additional components from a fake website and stealing sensitive data such as wallet recovery phrases, saved passwords, browsing history, and even Apple Notes on macOS.

Beyond the initial infection through PyPI, the campaign extends to other platforms, employing multiple social engineering tactics to lure victims.

The post Phantom Safe from Solana Web3.js Bug; Upgrade to 1.95.8 Urged appeared first on Cryptonews.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Ripple’s $RLUSD launch is delayed pending final NYDFS approval Nellius Irene | usagoldmines.com
Amazon (AWS) Partners with SonarX to Provide Free, Public Access to Blockchain Data Sead Fadilpašić ...
Regulators Plan to Allow S Korean Universities to ‘Trade’ Crypto, Companies to Follow Tim Alper | us...
Top Crypto Gainers Today on DEXTools – JEETMAS, CHAINSAW Hassan Shittu | usagoldmines.com
Bitcoin Price To $100,000: Why Reclaiming The $96,400 Level Is Very Important For Another Rally Scot...
Ethiopia’s Bitcoin mining surge now accounts for 2.5% of global hash rate Oluwapelumi Adejumo | usag...
Nuvei Unveils Blockchain Payment Solution in LATAM with Stablecoin Support Hassan Shittu | usagoldmi...
US Govt Moves 54.9 billion Shiba Inu, But SHIB Could Explode By 130% Jake Simmons | usagoldmines.com
Hut 8 to fund Bitcoin reserve plan via $500 million equity offering Gino Matos | usagoldmines.com
Salesforce becomes latest to ride AI wave as Agentforce powers stock surge Hannah Collymore | usagol...
Altcoin searches soar as Bitcoin holds steady at $97K, searches hit record high Brenda Kanana | usag...
Top Pundit Warns Ripple’s XRP Could Still Crash Back Below $0.60 Despite Recent Stunning Rally Brend...
Fear Looms Over Potential Bitcoin Price Dip After United States Govt Moved 19,800 BTC Aliyu Pokima |...
Roger Ver “Bitcoin Jesus” files motion to dismiss justice department indictment Brenda Kanana | usag...
Fed chair Powell views Bitcoin as digital gold, not a dollar competitor Gino Matos | usagoldmines.co...
China’s AI boom raises 2 massive censorship red flags Shraddha Sharma | usagoldmines.com
Cardano introduces plan 529 ahead of Plomin hard fork upgrade Brenda Kanana | usagoldmines.com
Trends in 2025: a16z predicts AI agents, crypto app stores and better prediction markets Hristina Va...
Crypto regulations, security risk buzzes India Blockchain week Ashish Kumar | usagoldmines.com
Crypto YouTube hits a 12-month high at 4.72M weekly views as retail interest rekindles Nellius Irene...
IcomTech Promoter Sentenced To Decade In Federal Prison Julia Smith | usagoldmines.com
Altcoins In The Spotlight As Bitcoin Dominance Flashes Sell Signal Christian Encila | usagoldmines.c...
Congressman French Hill vows to probe banking exclusion of crypto businesses Assad Jafri | usagoldmi...
Dogecoin Price Continues Trading Sideways But Bullish Pennant Says Get Ready For $1.30 Scott Mathers...
New York Mayor Eric Adams has the last laugh as Bitcoin hovers near $100k Gino Matos | usagoldmines....
Big $KOII Airdrop for Solana Seeker Pre-Orders Victor | usagoldmines.com
3 Top Low-Cap Altcoins: Best to Buy Now Stu L | usagoldmines.com
Coinbase Assets adds Gigachad (GIGA) and Turbo (TURBO) to its roadmap Hristina Vasileva | usagoldmin...
Citadel CEO Ken Griffin says he regrets not buying crypto in its bear market Florence Muchai | usago...
XRP’s meticulous 80% rise in 7 days: Is Forbes’ ‘Zombie Token’ list the next inverse fund bet? Shrad...
Putin says America is “eroding the foundation of its own economic dominance” Jai Hamid | usagoldmine...
Vestra DAO (VSTR) smart contract exploited less than a month after its launch Hristina Vasileva | us...
2 IcomTech Ponzi scheme promoters sentenced to 10 years in prison Florence Muchai | usagoldmines.com
Music Group Abba’s co-founder says ‘very unfair’ AI poses threat to artists revenue Hannah Collymore...
Donald Trump officially appoints pro-crypto Paul Atkins to replace Gary Gensler as SEC Chair Florenc...
Shibarium Upgrade Sparks SHIB Rally – Can It Propel Shiba Inu to $1? Hassan Shittu | usagoldmines.co...
Sol Strategies Sets the Stage for Growth with New Validator Acquisition Hassan Shittu | usagoldmines...
Binance Coin Hits All-Time High With Market Buzz Growing Around a New Coin Launch Tim Hakki | usagol...
Donald Trump Considering Caroline Pham, Perianne Boring for CFTC Chair Julia Smith | usagoldmines.co...
Why Are XRP and Cardano Going Up? This Low Cap Utility Token Blasts Past $2M In ICO  Tim Hakki | usa...
Grayscale’s Spot Solana ETF Could Ignite SOL to $400 – Here’s Why Bulls Are Watching Simon Chandler ...
BIT Mining Continues Focus on Litecoin and Dogecoin Mining Hongji Feng | usagoldmines.com
Dogecoin Is ‘Ready To Run Again’ – Analyst Expects 60% Rally Sebastian Villafuerte | usagoldmines.co...
Unyted + Vesa Vesa | usagoldmines.com
Trump confirms nomination of Paul Atkins as the new SEC chair Gino Matos | usagoldmines.com
Putin says Bitcoin is inevitable, endorses BTC over US dollar as global reserve currency Assad Jafri...
Tron’s TRX Copies XRP With Epic 70% Price Explosion To New All-Time High Of $0.43 Brenda Ngari | usa...
Michael Saylor Goes Mega Bullish, Points to $180,000 Bitcoin Price Aliyu Pokima | usagoldmines.com
Flockerz Raises $4.3M in Presale, Set to Become the Next Meme Coin Like $PNUT – $1B Market Cap Poten...
XRP Traders Rotate Profits Into Trending Meme Coin Catslap, $SLAP Price up 272% in 7 Days, CEX Listi...
BNB Price Surge: Upbeat Momentum Builds After $724 Breakout Godspower Owie | usagoldmines.com
South Korea’s crypto volumes spike as Woori eyes over $300 million Upbit exit Oluwapelumi Adejumo | ...
2024’s top performing layer 1 networks: CoinGecko report Florence Muchai | usagoldmines.com
The global economy might miss its chance for growth recovery next year, says OECD Jai Hamid | usagol...
The Fed’s reaction to Trump’s tariffs will be powerful – and quite negative Jai Hamid | usagoldmines...
Russia’s president Putin goes full-on pro-crypto, says no one can ban Bitcoin Jai Hamid | usagoldmin...
Exchange tokens BNB, BGB, and GT hit all-time high (ATH) levels Florence Muchai | usagoldmines.com
Tron to adopt MicroStrategy’s playbook Brenda Kanana | usagoldmines.com
Ripple’s RLUSD stablecoin launch set for Dec 2024 – Here’s all you need to know before the launch Fl...
Regulatory uncertainty to blame for dismal uptake of stablecoins in global e-commerce Nellius Irene ...
Crypto’s Biggest Ever Meme Coin Presale Pepe Unchained ($PEPU) Raises an Unprecedented $70 Million a...
XRP Surges Amid Bullish Wedge Pattern – Analyst Claims It Will Never Drop ‘Below $2 Again’ Simon Cha...
Best Crypto to Buy Now December 4 – TRX, HYPE, MNT Jimmy Aki | usagoldmines.com
Safe Aims for Visa-Like Crypto Payments with Safenet Cross-Chain Transactions Hassan Shittu | usagol...
U.S. Government Transfers $33.6 Million in Seized FTX Crypto to Strange Addresses Jimmy Aki | usagol...
PEPE Price Surges 128% in November, While WEPE Token Presale Storms to $400K – Could $WEPE Be Decemb...
Hut 8 Launches $500M ATM Program and $250M Stock Repurchase Plan Hongji Feng | usagoldmines.com
The Fed’s reaction to Trump’s tariffs will be powerful – and quite negative Jai Hamid | usagoldmines...
$1.87B Bitcoin Withdrawals From Coinbase In 24H – What This Means To Price Sebastian Villafuerte | u...
Ethereum Price Is About To Confirm A Golden Cross On The Daily Time Frame, Here’s What Happened Last...
2024’s top performing layer 1 networks: CoinGecko report Florence Muchai | usagoldmines.com
Ripple, Cardano lead altcoin surge as market cap nearly doubles to $1.55 trillion Oluwapelumi Adejum...
Australia’s ASIC explores stablecoins, wrapped tokens in new crypto framework Oluwapelumi Adejumo | ...
PancakeSwap introduces SpringBoard, its own meme token launch platform Hristina Vasileva | usagoldmi...
Argo Blockchain Records $3.4 Million Revenue Despite Decline in Bitcoin Mining Jimmy Aki | usagoldmi...
Bitcoin Price Action Forms ‘Symmetrical Triangle’ Pattern – Breakout to $100,000 Incoming? Simon Cha...
XRP Under The Microscope: Will It Break $2.9? Key Support Levels And Future Targets Ronaldo Marquez ...
Phantom Wallet Simplifies Crypto with Email and PIN Victor | usagoldmines.com
GAIB Secures $5M to Create AI Compute Economic Layer Victor | usagoldmines.com
Magic Eden Launches on Sei Network Victor | usagoldmines.com
Celebrating Crypto’s Early Icons: BTCC OG Week Honors Bitcoin and Meme Coin Pioneers KEY Difference ...
Australia’s ASIC proposes updates to crypto asset guidance Vignesh Karunanidhi | usagoldmines.com
Britain plans to take on the US as a global crypto hub — but can they? Florence Muchai | usagoldmine...
Bank of Korea Governor says interest rate cuts unlikely after unprecedented political unrest Florenc...
Tezos Aims to Democratize Uranium Trading with Blockchain-Based Uranium.io Platform Ruholamin Haqsha...
U.S. Spot Bitcoin ETFs See $676M in Inflows as Holdings Surpass 1M BTC Ruholamin Haqshanas | usagold...
If Dogecoin Mirrors Last Cycle, The Surge To $4 Begins At Week’s End Jake Simmons | usagoldmines.com
After Ripple’s XRP surge price now compares to America’s top 100 companies by market cap Oluwapelumi...
PancakeSwap Reveals No-Code Token Launchpad Platform ‘SpringBoard’ Sead Fadilpašić | usagoldmines.co...
Missouri Senate introduces bill to disqualify CBDCs as legal tender Liam 'Akiba' Wright | usagoldmin...
Bitcoin Well Adopts Canada’s First Bitcoin Treasury Victor | usagoldmines.com
Former Celsius CEO Alex Mashinsky Pleads Guilty to Fraud Victor | usagoldmines.com
Why is the crypto market down today? Liquidations near $600M, and bulls take a rest Florence Muchai ...
Whales are accumulating Solana (SOL) and Pepe (PEPE), what may be the reason? Hristina Vasileva | us...
Whale Activity Sparks Chainlink Rally, $52 Target On Traders’ Radar Christian Encila | usagoldmines....
Coinbase faces backlash over discouraging VPN access due to security concerns Oluwapelumi Adejumo | ...
Bitcoin Drops 30% on Upbit Amid South Korean Martial Law Victor | usagoldmines.com
South Korea Delays Crypto Tax for Two Years Victor | usagoldmines.com
Dubai’s virtual asset regulator issues alert against XT.com and six other crypto entities Lara Abdul...
South Korean Won strengthens, while XRP, BTC, and equities tank amid calls for the president to step...

Leave a Reply