Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Ledger CTO Warns Wallet Holders After NPM Account Hack

Ledger CTO Warns Wallet Holders After NPM Account Hack

CryptotaleCryptotale2025/09/08 22:10
By:Yusuf Islam
Ledger CTO Warns Wallet Holders After NPM Account Hack image 0
  • A large attack hit JavaScript tools that are used by millions across crypto platforms.
  • Ledger CTO advised users to check every transaction and to avoid blind signing.
  • Developers were told to secure packages and stop auto-updates until fixes are complete.

A sweeping supply chain attack on the JavaScript ecosystem has rattled the crypto industry, exposing fragile dependencies across its infrastructure. On September 8, 2025, Ledger’s Chief Technology Officer, Charles Guillemet, confirmed that attackers had breached a reputable developer’s NPM (Node Package Manager) account. The compromised account allowed hackers to inject “crypto-clipper” malware into heavily used JavaScript packages. 

NEW: LEDGER CTO SAYS "IF YOU USE A HARDWARE WALLET, PAY ATTENTION TO EVERY TRANSACTION BEFORE SIGNING AND YOU'RE SAFE.IF YOU DON’T USE A HARDWARE WALLET, REFRAIN FROM MAKING ANY ON-CHAIN TRANSACTIONS FOR NOW"

— DEGEN NEWS September 8, 2025

These infected libraries, including chalk, debug, strip-ansi, and color-convert, collectively account for more than one billion downloads, showing the immense scale of exposure. According to Guillemet, the malicious code silently swaps crypto wallet addresses during transactions, sending funds to attacker-controlled accounts. This means unsuspecting users are able to complete transactions believing them legitimate while unknowingly losing assets.

The affected tools were anything but obscure. Libraries, such as Chalk and Debug, support numerous decentralized applications and crypto platforms and are, thus, intimately involved in the daily running of the ecosystem. A breach of these libraries signaled that one breach can quickly affect millions of wallets and applications.

Urgent Warnings from Ledger CTO

Guillemet did not name the developer whose account was compromised. Yet he made clear that the threat is extensive. “This is a large-scale supply chain attack. The entire JavaScript ecosystem may be affected,” he wrote in his official warning.

He stressed the importance of using hardware wallets with secure screens that support Clear Signing. “The only sure way to combat this is to use a hardware wallet with a secure screen that supports clear signing,” he said. “This will allow the user to see exactly which addresses funds are being sent to and ensure they match the intended addresses.”

Ledger CTO Warns Wallet Holders After NPM Account Hack image 1 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk.

The malicious payload works…

— Charles Guillemet September 8, 2025

He continued, “Hardware wallets without secure screens and any wallet that doesn’t support clear signing are at high risk, as it is impossible to accurately verify the transaction details are correct.”

Finally, he issued a broad reminder: “It’s an opportunity to remind everyone: always verify your transactions, never blind sign, use a hardware wallet with a secure screen, and Clear Sign everything.”

Response from Developers and Wider Implications

In the wake of the disclosure, developers have been urged to pin safe versions of dependencies, secure lockfiles, and halt auto-updating packages until further notice. These precautions are intended to contain the damage while audits and clean-ups proceed across the ecosystem. Prominent figures within the crypto developer community also advised users to avoid interacting with crypto websites until vulnerabilities are resolved.

Related: Ripple Developers Defend XRP Ledger Amid Kaiko Assessment

This event put forward that even critical wallet providers such as Ledger depend on software layers outside their immediate control. If such layers are compromised, then the resulting impact can be devastating. Users numbering in the millions and digital values amounting to billions may be at risk within hours.

Update on the NPM Attack

According to the latest update from Guillemet, the attack has failed and had almost no victims. It began with a phishing email from a fake npm support domain that stole credentials, giving attackers access to publish malicious package updates. The injected code targeted web crypto activity, hooking into Ethereum, Solana, and other chains to hijack transactions by replacing wallet addresses directly in network responses. However, the attackers’ mistakes caused crashes in CI/CD pipelines, which led to early detection and limited the impact.

Guillemet emphasized that if your funds are in a software wallet or on an exchange, you’re one code execution away from losing everything. Supply chain compromises remain a powerful malware delivery vector, and targeted attacks are on the rise. He also highlighted that hardware wallets are built to withstand these threats. Features like Clear Signing let you confirm exactly what’s happening, and Transaction Checks flag suspicious activity before it’s too late.

The post Ledger CTO Warns Wallet Holders After NPM Account Hack appeared first on Cryptotale.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Five charts to help you understand: Where does the market go after each policy storm?

After this regulatory crackdown, is it a harbinger of an impending downturn, or the beginning of a new cycle where all negative news has been fully priced in? Let’s examine the trajectory after the storm through five key policy milestones.

Biteye2025/12/10 07:33
Five charts to help you understand: Where does the market go after each policy storm?

Mars Morning News | The crypto market rebounds across the board, Bitcoin rises above $94,500; The "CLARITY Act" draft is expected to be released this week

The crypto market has fully rebounded, with bitcoin surpassing $94,500 and US crypto-related stocks rising across the board. The US Congress is advancing the CLARITY Act to regulate cryptocurrencies. The SEC chairman stated that many ICOs are not securities transactions. Whales are holding a large number of profitable ETH long positions. Summary generated by Mars AI. The accuracy and completeness of the content generated by the Mars AI model is still being iteratively updated.

MarsBit2025/12/10 06:35
Mars Morning News | The crypto market rebounds across the board, Bitcoin rises above $94,500; The "CLARITY Act" draft is expected to be released this week

Federal Reserve’s Major Shift: From QT to RMP, How Will the Market Transform by 2026?

The article discusses the background, mechanism, and impact on financial markets of the Federal Reserve's introduction of the Reserve Management Purchases (RMP) strategy after ending Quantitative Tightening (QT) in 2025. RMP is regarded as a technical operation aimed at maintaining liquidity in the financial system, but the market interprets it as a covert easing policy. The article analyzes RMP's potential effects on risk assets, the regulatory framework, and fiscal policy, and provides strategic recommendations for institutional investors. Summary generated by Mars AI This summary was generated by the Mars AI model, and the accuracy and completeness of its content are still in the process of iterative improvement.

MarsBit2025/12/10 06:35
Federal Reserve’s Major Shift: From QT to RMP, How Will the Market Transform by 2026?
© 2025 Bitget