RSS Amplifier

Web3sec News · Oct 31, 2025

Web3 Security Weekly

0
Sign in to vote or save

Chirag Agrawal · Web3sec News

Hey fam,

October’s closing out with a clear message, the biggest threats aren’t always in your smart contracts they’re in the code you never think to check. Between massive npm compromises, sophisticated phishing campaigns, and record-breaking exploits, September and October have been a masterclass in why layered security matters.

Venus Protocol user named Kuan Sun joined what seemed like a legitimate Zoom meeting. The attackers convinced him to install a malicious browser extension. Minutes later, $27 million in crypto vanished – including $19.8M in vUSDT, $7.15M in vUSDC, 285 BTCB, and more.

This wasn’t a smart contract exploit. It was pure social engineering: a fake Zoom app that granted attackers permission to drain the wallet through malicious token approvals. Security firm SlowMist later traced the attack to the Lazarus Group, North Korea’s state-sponsored hacking syndicate.

A special thanks to this week’s sponsor Coinspect.

Coinspect’s Wallet Security Ranking is an objective, transparent, and regularly updated evaluation of leading cryptocurrency wallets. It focuses on critical security features like anti-phishing defenses, transaction clarity, and protection against blind signing, helping users choose wallets that prioritize their safety.

Link: https://www.coinspect.com/wallets/

On September 8th, one of the largest supply chain attacks in history unfolded. Popular npm packages like debug and chalk – with over 2.6 billion weekly downloads combined – were compromised after a maintainer fell for a sophisticated phishing email from a fake domain (npmjs.help).

The injected malware was browser-focused, targeting crypto wallets by:

  • Hooking into window.ethereum to intercept MetaMask and other wallet requests

  • Redirecting transactions to attacker-controlled addresses

  • Using Levenshtein distance algorithms to replace blockchain addresses with visually similar ones

  • Supporting multiple chains: Ethereum, Bitcoin, Solana, Litecoin, Tron, and more

Ledger CTO Charles Guillemet issued an urgent warning to halt onchain transactions. Within 2 hours of discovery, maintainers reverted to clean versions – but the damage was done. Thousands of developers worldwide spent days auditing dependencies and cleaning compromised environments.

The irony? Despite affecting billions of downloads, the attacker only stole about 5 cents of ETH and $20 worth of a memecoin. The real cost was the collective thousands of engineering hours spent on cleanup.

October’s NuGet Attack on Nethereum

The attacks didn’t stop. On October 16th, attackers published malicious packages mimicking Nethereum (a popular .NET library for Ethereum development) on NuGet. The fake “NethereumNet” and “Netherеum.All” packages (note the subtle Cyrillic character) targeted crypto developers’ private keys.

Socket.dev researchers caught it on October 18th, and NuGet removed it by October 20th – but that 4-day window was enough for potential compromise.

  • Abracadabra Flash Loan Exploit - $1.8M (October 1st) The Abracadabra DeFi protocol, known for its Magic Internet Money (MIM) stablecoin, suffered a flash-loan exploit draining roughly $1.8 million. Flash loans continue to be a favorite attack vector for sophisticated exploiters.

  • Hyperliquid User Loses $21M (October 2025) A Hyperliquid user lost $21 million due to a private key breach. The stolen assets – 17.75M DAI and 3.11M MSYRUPUSDP – were swiftly bridged out. This incident underscores that even on cutting-edge L1 platforms, private key security remains the ultimate responsibility of users.

Applications for the EF 2026 Internship Program are now open.

A paid, full-time, 12-week opportunity to work directly with the teams advancing the Ethereum protocol and ecosystem.

Apply today.

DeFi Security Summit 2025November 20-21 in Buenos Aires, Argentina.

The ultimate gathering for white-hat hackers, auditors, and security researchers. Zero marketing, pure technical depth.

Full schedule: defisecuritysummit.org/schedule

Huge shoutout to our 27 Octant supporters! Your backing through the Octant grants program means everything. Thanks to quadratic matching, your support got multiplied significantly, keeping this newsletter free for the entire Web3 security community.

One fake Zoom meeting = $27M gone.

One phishing email to an npm maintainer = 2.6 billion weekly downloads compromised.

North Korean hackers stealing $2B in a single year.

The attack surface has shifted dramatically.

Key takeaways?

  • Off-chain attacks now account for 80.5% of stolen funds

  • Private key compromises represent 39% of all incidents

  • Supply chain vulnerabilities affect billions of users silently

  • State-sponsored actors are more active than ever

Action items for developers?

  • Audit your dependencies NOW

  • Enable strong 2FA on all package manager accounts

  • Never click links in unsolicited “urgent security” emails

  • Use hardware wallets or MPC solutions for significant holdings

  • Implement real-time monitoring for suspicious activity

Building DNS security tools for Web3?

Seen suspicious domain activity?

Want to share war stories?

Find me at @__Raiders - working on solutions to make this whole mess better.

P.S. – Got a security incident we should cover? Hit reply or tag us on Twitter. We’re tracking everything so you don’t have to.

No posts

Read the original on web3secnews.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.