We collect cookies to analyze our website traffic and performance; we never collect any personal data.Cookies Policy
Accept
Michigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
Reading: Solana dev library web3.js compromised to steal non-public keys
Share
Font ResizerAa
Michigan PostMichigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
© 2024 | The Michigan Post | All Rights Reserved.
Michigan Post > Blog > Crypto & Web 3 > Solana dev library web3.js compromised to steal non-public keys
Crypto & Web 3

Solana dev library web3.js compromised to steal non-public keys

By Editorial Board Published December 4, 2024 2 Min Read
Share
Solana dev library web3.js compromised to steal non-public keys

Solana’s web3.js library was compromised yesterday in a provide chain assault that put in malicious packages able to stealing the non-public keys of customers and draining their funds.  

Since then, a wave of Solana-based builders have come out to substantiate they aren’t impacted by the exploit. Unaffected companies embrace Solflare, Phantom Pockets, and Helium. 

Solana’s web3.js is a JavaScript library accessible to builders wanting to construct Solana-based apps. Experiences counsel that maintainers of the library could have been focused by a phishing marketing campaign as attackers gained entry to the “publish-access account.”

By way of this account, the attackers launched a personal key stealer into the 2 variations of Solana’s web3.js library with an ‘addToQueue’ perform that stole beneath the guise of Cloudflare headers. In line with Solscan, the attackers stole near $160,000.

Solana analysis agency Anza posted, “This is not an issue with the Solana protocol itself, but with a specific JavaScript client library.” 

It pressured it “only appears to affect projects that directly handle private keys and that updated within the window of 3:20pm UTC and 8:25pm UTC on Tuesday, December 2, 2024.”

It claims the 2 exploits had been “caught within hours and have since been unpublished,” and requested, “all Solana app developers to upgrade to version 1.95.8. Developers pinned to `latest` should also upgrade to 1.95.8.”

TAGGED:compromisedDevkeyslibraryprivateSolanastealweb3.js
Share This Article
Facebook Twitter Email Copy Link Print

HOT NEWS

Democrats Demand  Billion In International Spending To Reopen Authorities | Economics

Democrats Demand $5 Billion In International Spending To Reopen Authorities | Economics

Economics
October 16, 2025
1000’s sue Johnson & Johnson in UK over most cancers claims

1000’s sue Johnson & Johnson in UK over most cancers claims

Johnson & Johnson (J&J) is going through authorized motion from hundreds of individuals within the…

October 16, 2025
May Tomahawk missiles be a game-changer for Ukraine and will they strike Moscow?

May Tomahawk missiles be a game-changer for Ukraine and will they strike Moscow?

Donald Trump is contemplating supplying Tomahawk missiles to Ukraine - however what makes them completely…

October 16, 2025
Crime Stoppers: Three requests for info

Crime Stoppers: Three requests for info

LANSING, Mich. (WLNS) -- This week on Crime Stoppers, police want your assist discovering suspects…

October 16, 2025
China Retaliates Over Dutch Nexperia Seizure | Economics

China Retaliates Over Dutch Nexperia Seizure | Economics

The Dutch authorities believed it may stop China from stealing “crucial technological knowledge” by seizing…

October 16, 2025

YOU MAY ALSO LIKE

ZachXBT cracks Railgun privateness to show Bittensor hacker

Crypto sleuth ZachXBT has managed to deanonymise withdrawals from crypto mixer Railgun whereas figuring out a suspect linked to NFT…

Crypto & Web 3
October 15, 2025

Microsoft might stall Bitcoin growth through GitHub

Bitcoin builders flagged a person suspension this week by Microsoft’s GitHub for instance of the corporate’s disconcerting degree of management…

Crypto & Web 3
October 15, 2025

Binance itemizing price drama goes nuclear

Binance’s assist desk has deleted what it referred to as an “excessive” response to a tweet from Limitless Labs CEO…

Crypto & Web 3
October 15, 2025

$25 million Ethereum MEV exploit places ‘Code Is Law’ on trial

The trial of two brothers, Anton and James Peraire-Bueno, started yesterday at New York’s SDNY courthouse. The brothers, each of…

Crypto & Web 3
October 15, 2025

Welcome to Michigan Post, an esteemed publication of the Enspirers News Group. As a beacon of excellence in journalism, Michigan Post is committed to delivering unfiltered and comprehensive news coverage on World News, Politics, Business, Tech, and beyond.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • Accessibility Statement

Contact Us

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 | The Michigan Post | All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?