馃毃BREAKING:

#Ledger CTO Charles Guillemet warns of a supply chain #attack in the #JavaScript ecosystem after an #NPM account compromise.

He advises users to carefully verify every transaction if using a #hardware #wallet, and to avoid on-chain transactions entirely if they don鈥檛.

Stay safe.

馃毃 脷LTIMA HORA

El CTO de #Ledger, Charles Guillemet, advierte sobre un #ataque en curso: se comprometi贸 la cuenta de un desarrollador en #NPM, la mayor biblioteca de paquetes de #JavaScript usada por casi todo el ecosistema.

NPM es la base sobre la que se construyen miles de apps y servicios, incluidas muchas wallets. El exploit inserta c贸digo malicioso que cambia direcciones de env铆o de criptomonedas, lo que podr铆a afectar directamente a los usuarios.

Si usas #hardware #wallets, revisa cada transacci贸n antes de firmar. Si usas software wallets, evita de momento realizar operaciones on-chain hasta nueva informaci贸n.

#bitcoin #breaking #ultimahora

Reply to this note

Please Login to reply.

Discussion

How You Lose Your Funds

The malware uses two sophisticated methods:

- Clipboard Hijacking: When you paste a wallet address, it stealthily swaps it with an attacker's address that is visually similar to the real one, making it extremely hard to spot the difference.

- Transaction Interception: It directly hooks into your wallet's functions. When you go to sign a transaction, it changes the recipient's address in the background before the confirmation prompt even appears.

How to Protect Yourself

- This malware targets BTC, ETH, SOL, TRX, LTC, and BCH.

- Your final confirmation screen is your last line of defense.

- You must meticulously verify every single character of the recipient address in your wallet app or on your hardware wallet screen before approving any transaction.

El malware utiliza dos m茅todos sofisticados:

- Secuestro del portapapeles: cuando pegas la direcci贸n de una billetera, la intercambia sigilosamente con la direcci贸n de un atacante que es visualmente similar a la real, lo que hace que sea extremadamente dif铆cil detectar la diferencia.

Interceptaci贸n de transacciones: Intercepta directamente las funciones de tu billetera. Al firmar una transacci贸n, cambia la direcci贸n del destinatario en segundo plano incluso antes de que aparezca la solicitud de confirmaci贸n.

C贸mo protegerse:

- Este malware apunta a BTC, ETH, SOL, TRX, LTC y BCH.

- La pantalla de confirmaci贸n final es su 煤ltima l铆nea de defensa.

- Debe verificar meticulosamente cada car谩cter de la direcci贸n del destinatario en su aplicaci贸n de billetera o en la pantalla de su billetera de hardware antes de aprobar cualquier transacci贸n.

https://store.blockstream.com/?code=KgD7dk4Ejmt6

Check out the official announcements from Blockstream and Jade:

.

https://x.com/BlockstreamJade/status/1965147418242269232

.

https://x.com/Blockstream/status/1965160059908022319

.

https://x.com/Blockstream/status/1965162320625385897

The Blockstream app and the Jade hardware wallet are NOT affected; the app does not use JavaScript environments or NPM packages. Instead, it is built with Swift (iOS), Kotlin (Android), and C++ with QML (desktop/Qt), completely avoiding this vulnerability that affects packages with billions of downloads and that can swap crypto addresses to steal funds. This means that users' funds remain completely safe.

Jade is the Bitcoin-focused hardware wallet emphasizing transparency and isolation, compatible with apps like Blockstream Green for air-gapped transactions via QR codes.

Fully open-source code/hardware for community auditing, true air-gapped operation (no USB/Bluetooth for signing), and native Liquid network integration for sidechain assets like L-BTC/USDt.

Liquid is a federated Bitcoin sidechain second-layer solution designed for fast and private settlements, using confidential transactions to hide amounts and assets(However, the Blockstream Green Wallet has the option to route using Tor), and enabling the issuance of tokens. Unlike Lightning, it is not focused on instant micropayments, but rather on safer and more efficient movement of larger values.