Explained: how crypto's 'largest supply chain attack' stole just $0.05
A widespread security supply chain attack led to panic across the crypto community yesterday with users warned to “refrain from making any on-chain transactions.” Researchers at security firm Aikido raised the alarm after discovering that 18 popular node package manager (npm) packages contained malicious code. After being notified, the developer who maintains the popular npm packages, alias Qix, confirmed the compromise. He’d been “pwned” via a phishing email which “looked very legitimate.” Despite the packages being widespread across the crypto industry, the attack led to almost no losses. Samczsun, the head of Security Alliance, a blockchain security collective, called the result a “generational fumble.” my sincerest condolences to the person responsible for this, this was a generational fumble, the likes of which we will probably never see again https://t.co/nfiTU5K0Ig — samczsun (@samczsun) September 8, 2025 Read more: ‘Decentralized’ apps suff...