Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • Souvenirs, Gifts & Folk Art Travel Fair Joins Athens International, Thessaloniki Tourism, Crete, Greek Hospitality Investment Forum and More as Greece Ignites February with a Power-Packed Tourism Trade Takeover – Travel And Tour World
  • Bitcoin Is Crashing Again: Is It Finally Time to Buy This Top Cryptocurrency?
  • Tell us: how have you been affected by falling cryptocurrency prices? – The Guardian
  • Stock Trading and Investing Applications Business Research Report 2026: $150+ Bn Market Opportunities, Trends, Competitive Landscape, Strategies, and Forecasts, 2020-2025, 2025-2030F, 2035F – Yahoo Finance UK
  • ‘Crypto winter’: Why is Bitcoin crashing despite Trump’s support? – Al Jazeera
  • Ireland Loyalty Business Report 2026: A $355 Million Market by 2030 from $199.5 Million in 2025 – 100+ KPIs by Program Type, Channel Mix, Sector, Embedded Loyalty Penetration, and Platform Spend – Yahoo Finance UK
  • AI.com bought by Crypto.com founder for $70mn in biggest-ever website name deal
  • MHCLG ‘heard’ finance settlement business rates concerns
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»Malicious packages for dYdX cryptocurrency exchange empties user wallets
Cryptocurrency

Malicious packages for dYdX cryptocurrency exchange empties user wallets

February 6, 20262 Mins Read


Open source packages published on the npm and PyPI repositories were laced with code that stole wallet credentials from dYdX developers and backend systems and, in some cases, backdoored devices, researchers said.

“Every application using the compromised npm versions is at risk ….” the researchers, from security firm Socket, said Friday. “Direct impact includes complete wallet compromise and irreversible cryptocurrency theft. The attack scope includes all applications depending on the compromised versions and both developers testing with real credentials and production end-users.”

Packages that were infected were:

npm (@dydxprotocol/v4-client-js):

  • 3.4.1
  • 1.22.1
  • 1.15.2
  • 1.0.31

PyPI (dydx-v4-client):

Perpetual trading, perpetual targeting

dYdX is a decentralized derivatives exchange that supports hundreds of markets for “perpetual trading,” or the use of cryptocurrency to bet that the value of a derivative future will rise or fall. Socket said dYdX has processed over $1.5 trillion in trading volume over its lifetime, with an average trading volume of $200 million to $540 million and roughly $175 million in open interest. The exchange provides code libraries that allow third-party apps for trading bots, automated strategies, or backend services, all of which handle mnemonics or private keys for signing.

The npm malware embedded a malicious function in the legitimate package. When a seed phrase that underpins wallet security was processed, the function exfiltrated it, along with a fingerprint of the device running the app. The fingerprint allowed the threat actor to correlate stolen credentials to track victims across multiple compromises. The domain receiving the seed was dydx[.]priceoracle[.]site, which mimics the legitimate dYdX service at dydx[.]xyz through typosquatting.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin Is Crashing Again: Is It Finally Time to Buy This Top Cryptocurrency?

February 7, 2026 Cryptocurrency

Tell us: how have you been affected by falling cryptocurrency prices? – The Guardian

February 6, 2026 Cryptocurrency

‘Crypto winter’: Why is Bitcoin crashing despite Trump’s support? – Al Jazeera

February 6, 2026 Cryptocurrency

AI.com bought by Crypto.com founder for $70mn in biggest-ever website name deal

February 6, 2026 Cryptocurrency

As some tech stocks tumble, cryptocurrency goes over a cliff

February 6, 2026 Cryptocurrency

Wisconsin lawmakers propose cryptocurrency kiosk restrictions to prevent scams

February 6, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Souvenirs, Gifts & Folk Art Travel Fair Joins Athens International, Thessaloniki Tourism, Crete, Greek Hospitality Investment Forum and More as Greece Ignites February with a Power-Packed Tourism Trade Takeover – Travel And Tour World

February 7, 2026 Art Investment 1 Min Read

Souvenirs, Gifts & Folk Art Travel Fair Joins Athens International, Thessaloniki Tourism, Crete, Greek Hospitality…

Bitcoin Is Crashing Again: Is It Finally Time to Buy This Top Cryptocurrency?

February 7, 2026

Tell us: how have you been affected by falling cryptocurrency prices? – The Guardian

February 6, 2026

Stock Trading and Investing Applications Business Research Report 2026: $150+ Bn Market Opportunities, Trends, Competitive Landscape, Strategies, and Forecasts, 2020-2025, 2025-2030F, 2035F – Yahoo Finance UK

February 6, 2026
Our Picks

Souvenirs, Gifts & Folk Art Travel Fair Joins Athens International, Thessaloniki Tourism, Crete, Greek Hospitality Investment Forum and More as Greece Ignites February with a Power-Packed Tourism Trade Takeover – Travel And Tour World

February 7, 2026

Bitcoin Is Crashing Again: Is It Finally Time to Buy This Top Cryptocurrency?

February 7, 2026

Tell us: how have you been affected by falling cryptocurrency prices? – The Guardian

February 6, 2026

Stock Trading and Investing Applications Business Research Report 2026: $150+ Bn Market Opportunities, Trends, Competitive Landscape, Strategies, and Forecasts, 2020-2025, 2025-2030F, 2035F – Yahoo Finance UK

February 6, 2026
Our Picks

Wisconsin lawmakers propose cryptocurrency kiosk restrictions to prevent scams

February 6, 2026

Explained — Why the latest RBI announcement is positive for Manappuram and Muthoot Finance

February 6, 2026

AARP-WV urges lawmakers to pass legislation protecting consumers from cryptocurrency scams | News, Sports, Jobs

February 5, 2026
Latest updates

Souvenirs, Gifts & Folk Art Travel Fair Joins Athens International, Thessaloniki Tourism, Crete, Greek Hospitality Investment Forum and More as Greece Ignites February with a Power-Packed Tourism Trade Takeover – Travel And Tour World

February 7, 2026

Bitcoin Is Crashing Again: Is It Finally Time to Buy This Top Cryptocurrency?

February 7, 2026

Tell us: how have you been affected by falling cryptocurrency prices? – The Guardian

February 6, 2026
Weekly Updates

Cryptocurrency Fetch.ai Falls More Than 6% In 24 hours

June 28, 2024

Bitcoin ETF creates BTC history as new emerging cryptocurrency enters market

April 8, 2024

IDA21: Making Development Finance Work for Communities affected by Fragility, Conflict, and Violence – World

October 16, 2024
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.