A newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets. Cybersecurity researchersA newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets. Cybersecurity researchers

Second JavaScript Exploit in Four Months Exposes Crypto Sites to Wallet Drainers

A newly discovered loophole in one of the web’s most used development tools is giving hackers a new way to drain cryptocurrency wallets.

Cybersecurity researchers have reported a surge in malicious code uploaded to legitimate websites through a vulnerability in the popular JavaScript library React — a tool used by countless crypto platforms for their front-end systems.

Crypto Drainer Attacks Surge via React Flaw

According to Security Alliance (SEAL), a nonprofit cybersecurity organization, criminals are actively exploiting a recently disclosed React vulnerability labeled CVE-2025-55182.

“We are observing a big uptick in drainers uploaded to legitimate crypto websites through exploitation of the recent React CVE,” SEAL stated on X (formerly Twitter). “All websites should review front-end code for any suspicious assets NOW.

  • HP CEO “Exposes” Ink Cartridge Vulnerability Triggering Legal Storm
  • Exness Rewards Up to $10,000 in New Bug Bounty Program
  • How to Increase Business Security Using a Honeypot

The flaw enables unauthenticated remote code execution, allowing attackers to secretly inject wallet-draining scripts into websites. The malicious code tricks users into approving fake transactions via deceptive pop-ups or reward prompts.

Read more: Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads

SEAL cautioned that some compromised sites may be unexpectedly flagged as phishing risks. The organization advised web administrators to conduct immediate security audits to catch any injected assets or obfuscated JavaScript.

"If your project is getting blocked, that may be the reason. Please review your code first before requesting phishing page warning removal. The attack is targeting not only Web3 protocols! All websites are at risk. Users should exercise caution when signing ANY permit signature."

Phishing Flags and Hidden Drainers

The group warned that developers who find their projects mistakenly blocked as phishing pages should inspect their code first before appealing the warning.

The React development team confirmed on December 3 that it had patched the vulnerability after white hat hacker Lachlan Davidson privately reported the issue.

The fix affects the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages. The team urged all developers using these components to update immediately.

Market Opportunity
MetaDOS Logo
MetaDOS Price(SECOND)
$0.0000038
$0.0000038$0.0000038
0.00%
USD
MetaDOS (SECOND) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BitMine Expands Treasury Holdings with $140 Million Ethereum Acquisition

BitMine Expands Treasury Holdings with $140 Million Ethereum Acquisition

BitMine has significantly bolstered its cryptocurrency treasury with the acquisition of 48,049 ETH, valued at approximately $140 million at current market prices. The substantial purchase positions the company among a growing cohort of corporations holding Ethereum as a strategic reserve asset, extending a trend previously dominated by Bitcoin treasury strategies.
Share
MEXC NEWS2025/12/17 17:19
Hyper Foundation Proposes Validator Vote to Burn Assistance Fund Tokens

Hyper Foundation Proposes Validator Vote to Burn Assistance Fund Tokens

The Hyper Foundation has put forward a proposal for validators to vote on burning the $HYPE tokens currently held in the project's Assistance Fund. If approved, the burn would permanently remove these tokens from circulating supply, representing a significant shift in the protocol's token economics and treasury management philosophy.
Share
MEXC NEWS2025/12/17 17:21
This Altcoin Could 1000x By 2026

This Altcoin Could 1000x By 2026

The post This Altcoin Could 1000x By 2026 appeared on BitcoinEthereumNews.com. The SEC has approved a framework for the streamlined adoption of digital asset products in the United States on Wednesday, allowing exchanges to list and trade commodity-based trust shares without requiring a rule change to be filed first. This marks a significant milestone, opening the door for a surge in spot altcoin ETFs in the coming months. As a result, anticipation is building around institutional liquidity flows to the altcoin market – but which projects could perform the best?  Many analysts are betting on Bitcoin Hyper (HYPER) as a potential 1000x opportunity. It has not yet launched on exchanges, so it’s not immediately eligible for a spot ETF like some of the larger altcoins. That said, its use case positions it at the forefront of blockchain innovation, which signals huge potential for price gains as institutional capital rotates through the altcoin market. The project is developing the world’s first ZK-rollup-powered Bitcoin Layer 2 blockchain, addressing Bitcoin’s key issues of slow speeds and limited functionality while maintaining its renowned characteristics of security and immutability. SEC Approves Generic ETF Listing Standards The SEC has approved a proposed 19b-4 rule change from Cboe’s BZX exchange, Nasdaq, and NYSE Arca to standardize listing requirements for crypto exchange-traded products (ETPs) and streamline the process for public trading. According to Bloomberg ETF expert James Seyffart, this move paves the way for a “wave of spot crypto ETP launches in the coming weeks and months.” WOW. The SEC has approved Generic Listing Standards for “Commodity Based Trust Shares” aka includes crypto ETPs. This is the crypto ETP framework we’ve been waiting for. Get ready for a wave of spot crypto ETP launches in coming weeks and months. pic.twitter.com/xDKCuj41mc — James Seyffart (@JSeyff) September 17, 2025 Under the new listing standards, commodities must meet one of three conditions…
Share
BitcoinEthereumNews2025/09/19 07:09