We collect cookies to analyze our website traffic and performance; we never collect any personal data.Cookies Policy
Accept
Michigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
Reading: Solana dev library web3.js compromised to steal non-public keys
Share
Font ResizerAa
Michigan PostMichigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
© 2024 | The Michigan Post | All Rights Reserved.
Michigan Post > Blog > Crypto & Web 3 > Solana dev library web3.js compromised to steal non-public keys
Crypto & Web 3

Solana dev library web3.js compromised to steal non-public keys

By Editorial Board Published December 4, 2024 2 Min Read
Share
Solana dev library web3.js compromised to steal non-public keys

Solana dev library web3.js compromised to steal non-public keys

Solana’s web3.js library was compromised yesterday in a provide chain assault that put in malicious packages able to stealing the non-public keys of customers and draining their funds.  

Since then, a wave of Solana-based builders have come out to substantiate they aren’t impacted by the exploit. Unaffected companies embrace Solflare, Phantom Pockets, and Helium. 

Solana’s web3.js is a JavaScript library accessible to builders wanting to construct Solana-based apps. Experiences counsel that maintainers of the library could have been focused by a phishing marketing campaign as attackers gained entry to the “publish-access account.”

By way of this account, the attackers launched a personal key stealer into the 2 variations of Solana’s web3.js library with an ‘addToQueue’ perform that stole beneath the guise of Cloudflare headers. In line with Solscan, the attackers stole near $160,000.

Solana analysis agency Anza posted, “This is not an issue with the Solana protocol itself, but with a specific JavaScript client library.” 

It pressured it “only appears to affect projects that directly handle private keys and that updated within the window of 3:20pm UTC and 8:25pm UTC on Tuesday, December 2, 2024.”

It claims the 2 exploits had been “caught within hours and have since been unpublished,” and requested, “all Solana app developers to upgrade to version 1.95.8. Developers pinned to `latest` should also upgrade to 1.95.8.”

TAGGED:compromisedDevkeyslibraryprivateSolanastealweb3.js
Share This Article
Facebook Twitter Email Copy Link Print

HOT NEWS

Ioannis Antypas on Helping Businesses Expand Into Saudi Arabia and the Middle East

Ioannis Antypas on Helping Businesses Expand Into Saudi Arabia and the Middle East

BusinessTrending
January 3, 2026
Vintage Rare USA: A Curated Archive of Iconic American Style

Vintage Rare USA: A Curated Archive of Iconic American Style

True vintage is not about trends—it’s about authenticity, heritage, and character. Vintage Rare USA has…

December 25, 2025
Omri Raiter: AI and Fusion Are Becoming Core Tools Against the Next Generation of Crime

Omri Raiter: AI and Fusion Are Becoming Core Tools Against the Next Generation of Crime

By Omri Raiter, Founder and CEO of RAKIA Group The next generation of organized crime…

December 24, 2025
Ocado chair joins Visma board forward of €20bn London float

Ocado chair joins Visma board forward of €20bn London float

The chairman of Ocado Group has been recruited to the board of Visma, the European…

December 18, 2025
Unique: Minnie Driver Proves 55 Is the New Fabulous – Beauty

Unique: Minnie Driver Proves 55 Is the New Fabulous – Beauty

Minnie Driver is in a second of full-flight momentum, getting into a vivid, confident period…

December 18, 2025

YOU MAY ALSO LIKE

The Block Mine Emerges as a Global Mining Powerhouse—Ushering in a New Era of Digital Asset Infrastructure with Nexa

The global blockchain economy is entering its next great phase—and The Block Mine is standing at the center of it.…

Crypto & Web 3Trending
December 18, 2025

Cathie Wooden falls for AI slop regardless of heavy OpenAI, Tempus bets

Cathie Wooden, the Ark Make investments CEO who heralded AI as “the most transformative technology in history” whereas investing tens…

Crypto & Web 3
December 18, 2025

Aave Labs v DAO: Who controls the cash — and the model?

The talk between Aave DAO and Aave Labs continues to escalate. In what started as a spat over the “private…

Crypto & Web 3
December 17, 2025

Ex-Alameda CEO Caroline Ellison leaves federal jail after 11 months

Caroline Ellison, the previous co-CEO of Alameda Analysis, is not behind bars after being moved to a midway home lower…

Crypto & Web 3
December 17, 2025

Welcome to Michigan Post, an esteemed publication of the Enspirers News Group. As a beacon of excellence in journalism, Michigan Post is committed to delivering unfiltered and comprehensive news coverage on World News, Politics, Business, Tech, and beyond.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • Accessibility Statement

Contact Us

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 | The Michigan Post | All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?