Hey fam,
October’s closing out with a clear message, the biggest threats aren’t always in your smart contracts they’re in the code you never think to check. Between massive npm compromises, sophisticated phishing campaigns, and record-breaking exploits, September and October have been a masterclass in why layered security matters.
Venus Protocol user named Kuan Sun joined what seemed like a legitimate Zoom meeting. The attackers convinced him to install a malicious browser extension. Minutes later, $27 million in crypto vanished – including $19.8M in vUSDT, $7.15M in vUSDC, 285 BTCB, and more.
This wasn’t a smart contract exploit. It was pure social engineering: a fake Zoom app that granted attackers permission to drain the wallet through malicious token approvals. Security firm SlowMist later traced the attack to the Lazarus Group, North Korea’s state-sponsored hacking syndicate.
A special thanks to this week’s sponsor Coinspect.
Coinspect’s Wallet Security Ranking is an objective, transparent, and regularly updated evaluation of leading cryptocurrency wallets. It focuses on critical security features like anti-phishing defenses, transaction clarity, and protection against blind signing, helping users choose wallets that prioritize their safety.
Link: https://www.coinspect.com/wallets/
On September 8th, one of the largest supply chain attacks in history unfolded. Popular npm packages like debug and chalk – with over 2.6 billion weekly downloads combined – were compromised after a maintainer fell for a sophisticated phishing email from a fake domain (npmjs.help).
The injected malware was browser-focused, targeting crypto wallets by:
Hooking into window.ethereum to intercept MetaMask and other wallet requests
Redirecting transactions to attacker-controlled addresses
Using Levenshtein distance algorithms to replace blockchain addresses with visually similar ones
Supporting multiple chains: Ethereum, Bitcoin, Solana, Litecoin, Tron, and more
Ledger CTO Charles Guillemet issued an urgent warning to halt onchain transactions. Within 2 hours of discovery, maintainers reverted to clean versions – but the damage was done. Thousands of developers worldwide spent days auditing dependencies and cleaning compromised environments.
The irony? Despite affecting billions of downloads, the attacker only stole about 5 cents of ETH and $20 worth of a memecoin. The real cost was the collective thousands of engineering hours spent on cleanup.
October’s NuGet Attack on Nethereum
The attacks didn’t stop. On October 16th, attackers published malicious packages mimicking Nethereum (a popular .NET library for Ethereum development) on NuGet. The fake “NethereumNet” and “Netherеum.All” packages (note the subtle Cyrillic character) targeted crypto developers’ private keys.
Socket.dev researchers caught it on October 18th, and NuGet removed it by October 20th – but that 4-day window was enough for potential compromise.
Abracadabra Flash Loan Exploit - $1.8M (October 1st) The Abracadabra DeFi protocol, known for its Magic Internet Money (MIM) stablecoin, suffered a flash-loan exploit draining roughly $1.8 million. Flash loans continue to be a favorite attack vector for sophisticated exploiters.
Hyperliquid User Loses $21M (October 2025) A Hyperliquid user lost $21 million due to a private key breach. The stolen assets – 17.75M DAI and 3.11M MSYRUPUSDP – were swiftly bridged out. This incident underscores that even on cutting-edge L1 platforms, private key security remains the ultimate responsibility of users.
Applications for the EF 2026 Internship Program are now open.
A paid, full-time, 12-week opportunity to work directly with the teams advancing the Ethereum protocol and ecosystem.
Apply today.
DeFi Security Summit 2025 – November 20-21 in Buenos Aires, Argentina.
The ultimate gathering for white-hat hackers, auditors, and security researchers. Zero marketing, pure technical depth.
Full schedule: defisecuritysummit.org/schedule
Cypherpunks still code tools to vanish. The quiet future belongs to ghosts
Hound: Relation-First Knowledge Graphs for Complex-System Reasoning in Security Audits
Fuzzing harness for Solana Vaults using Pinocchio and Honggfuzz.
V12: the only autonomous Solidity auditor that actually finds Highs and Criticals.
5 levels of automation, from fully manual to fully autonomous.
Supply chain attacks are targeting Web3: What the September npm hack reveals
Web3 Phishing Challenge including Simulations
SANS Challenge Coins
Security Boulevard Challenges
Huge shoutout to our 27 Octant supporters! Your backing through the Octant grants program means everything. Thanks to quadratic matching, your support got multiplied significantly, keeping this newsletter free for the entire Web3 security community.
One fake Zoom meeting = $27M gone.
One phishing email to an npm maintainer = 2.6 billion weekly downloads compromised.
North Korean hackers stealing $2B in a single year.
The attack surface has shifted dramatically.
Key takeaways?
Off-chain attacks now account for 80.5% of stolen funds
Private key compromises represent 39% of all incidents
Supply chain vulnerabilities affect billions of users silently
State-sponsored actors are more active than ever
Action items for developers?
Audit your dependencies NOW
Enable strong 2FA on all package manager accounts
Never click links in unsolicited “urgent security” emails
Use hardware wallets or MPC solutions for significant holdings
Implement real-time monitoring for suspicious activity
Building DNS security tools for Web3?
Seen suspicious domain activity?
Want to share war stories?
Find me at @__Raiders - working on solutions to make this whole mess better.
P.S. – Got a security incident we should cover? Hit reply or tag us on Twitter. We’re tracking everything so you don’t have to.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.