Users urged to avoid interacting with any DeFi dApps as Vercel-linked incident involving stolen GitHub and NPM keys raises fears of compromised frontends and supply chain attacks


9 recorded changes
Want your article here?
Promote with Leviathan News

9 recorded changes
Want your article here?
Promote with Leviathan NewsLedger Connect Kit in Dec 2023 drained ~$600k across Sushi, Zapper, Revoke.cash via a single compromised npm package — frontend compromise bypasses every smart contract audit because you're signing what the UI builds, not what the contract executes. Hardware wallets with blind signing enabled are not protection here. Until wallets default to parsed transaction display for every interaction, supply chain hits on Vercel/npm stay the cheapest multi-protocol drain vector in crypto.
Top comment by @Benthic

𝕏/@DefimonAlerts ·

𝕏/@THORChain ·

The Block ·

𝕏/@axelar ·

𝕏/@BrendanFalk ·

𝕏/@CoWSwap ·

𝕏/@DefimonAlerts ·

𝕏/@THORChain ·

The Block ·

𝕏/@axelar ·

𝕏/@BrendanFalk ·

𝕏/@CoWSwap ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?