North Korean developers hijack dormant Waves repository, plant credential-stealing code in wallet update

2025/06/19 17:05

PANews reported on June 19 that according to Cryptoslate, a North Korean developer has obtained advanced permissions in the Keeper-Wallet code base of Waves Protocol. The account "AhegaoXXX" has pushed updates to the dormant code base since May 2025. The account has been confirmed to be associated with North Korea's IT outsourcing organization. Code review found that a commit added the function of sending wallet logs and runtime errors to an external database, which may steal mnemonics and private keys. Although the branch has not been merged, the attacker has released six malicious NPM packages that have not been updated for a long time by controlling the account of former Waves engineer Maxim Smolyakov.

The security report pointed out that this incident shows that North Korean hackers have shifted from ordinary outsourcing infiltration to direct control of code bases. It is recommended that the development team strengthen supply chain protection, including auditing contributor permissions, cleaning dormant accounts, and monitoring repository redirection. Currently, the download volume of the affected software is low, but Waves users who update Keeper-Wallet are at risk of credential leakage.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

ETH Drops 5.77% Amid Coldware’s Scalable RWA Ecosystem Attracting New Buyers

ETH Drops 5.77% Amid Coldware’s Scalable RWA Ecosystem Attracting New Buyers

The post ETH Drops 5.77% Amid Coldware’s Scalable RWA Ecosystem Attracting New Buyers appeared on BitcoinEthereumNews.com. Table of contents 1. Investors Diversify Beyond Ethereum 2. Conclusion Show more Ethereum (ETH) has seen a sharp 5.77% decline as part of the wider crypto market pullback following recent highs. ETH now trades near $4,350 after nearly touching its all-time high of $4,900. Analysts point to $1.7 billion in long futures liquidations as leverage unwound across the sector. Despite this correction, Ethereum’s role in powering decentralized finance (DeFi) and stablecoins remains strong, with J.P. Morgan recently highlighting ETH as the most direct way to gain exposure to the booming $264 billion stablecoin market. While Ethereum undergoes profit-taking, Coldware (COLD) has become a magnet for investors seeking utility-rich ecosystems. The project’s Real World Asset (RWA) integration and scalable blockchain infrastructure are attracting newcomers looking for growth opportunities not tied to ETH’s current market cycle. Coldware’s vision includes Web3 mobile devices, secure hardware integration, and financial tools built for real-world adoption — positioning it as more than just another speculative presale. RWA Integration and Real Adoption Coldware’s RWA ecosystem is particularly appealing to new buyers as it promises to bridge digital assets with tangible economic value. By supporting tokenization of physical and financial assets, Coldware opens the door for mainstream businesses to leverage blockchain without relying on high Ethereum gas fees or complex Layer-2 solutions. This practical angle has allowed Coldware (COLD) to attract investors who believe RWA utility could drive the next wave of crypto mass adoption. Investors Diversify Beyond Ethereum For many traders, Coldware (COLD) offers a chance to diversify portfolios while Ethereum consolidates. ETH’s dominance and utility remain undeniable, but fresh capital is flowing toward scalable alternatives. Coldware’s combination of RWA, Web3 hardware, and investor-friendly tokenomics positions it as a credible competitor during a period when investors are eager for early-stage plays with 100X potential. Conclusion Ethereum’s (ETH)…
Share
BitcoinEthereumNews2025/08/20 07:02
Share