The post Critical React flaw triggers a wave of crypto wallet drainers appeared on BitcoinEthereumNews.com. Security Alliance (SEAL) have issued a warning that The post Critical React flaw triggers a wave of crypto wallet drainers appeared on BitcoinEthereumNews.com. Security Alliance (SEAL) have issued a warning that

Critical React flaw triggers a wave of crypto wallet drainers

Security Alliance (SEAL) have issued a warning that hackers are exploiting a serious React vulnerability to take over cryptocurrency websites. The SEAL stated that the vulnerability is fueling a surge of wallet-draining attacks that put users and platforms at immediate risk.

React Server Components (RSCs) feed the rendered result to clients (browsers) while operating on the server, rather than in the browser. However, the React team discovered a critical vulnerability with a maximum severity rating of 10 out of 10 in these packages.

Unpatched React servers risk remote code execution attacks

The React team issued an advisory stating that the vulnerability, known as React2Shell and listed as CVE-2025-55182, allows attackers to remotely execute code on compromised servers without requiring authentication. React’s maintainers reported the vulnerability on December 3 and assigned it the highest possible severity score.

According to the React team, CVE-2025-55182, affects the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages in versions 19.0, 19.1.0, 19.1.1, and 19.2.0.

SEAL urged that “All websites should review front-end code for any suspicious assets NOW.” The SEAL further stated that users should exercise caution when signing any crypto-related permission signature, as all websites, not just those using Web3 protocols, are vulnerable.

According to SEAL, all web development teams should scan hosts for CVE-2025-55182 and see if their code is unexpectedly loading assets from unknown hosts. Seal further instructed that teams should confirm the wallet displays the correct recipient on the signature signing request. The teams should also determine whether any of the “Scripts” loaded by their code are obfuscated JavaScript.

Shortly after the disclosure of CVE-2025-55182, SEAl found two more vulnerabilities in React Server Components while testing the previous patch. According to the React blog, SEAL disclosed CVE-2025-55184 and CVE-2025-67779 (CVSS 7.5), which are identified as Denial of Service and High Severity vulnerabilities. Next, SEAL disclosed CVE-2025-55183 (CVSS 5.3) which the researchers identified as Source Code Exposure and Medium Severity.

The React team advised that all websites should upgrade immediately due to the seriousness of the recently revealed vulnerabilities.

According to JS’s advisory, the denial-of-service vulnerability, identified as CVE-2025-55184, allows attackers to create malicious HTTP requests and send them to any App Router or Server Function endpoint. The report further explained that these requests create an endless loop that hangs the server process and prevents future HTTP requests from being served.

According to the Common Vulnerability Scoring System (CVSS), CVE-2025-55184 carries a high severity score of 7.5 out of 10.

CVE-2025-55183, the second source code leakage vulnerability, has a medium severity rating of 5.3 out of 10.

According to Next.js, the exploit chain would be similar. Next.js explained that a susceptible endpoint receives a specially constructed HTTP request from the attacker, which returns the source code of any Server Function. Next. js team cautioned that hardcoded secrets and the company’s logic could be exposed by disclosing generated source code.

Crypto drainers refine evasion tactics for stealthy crypto theft

The rise in drainers, facilitated by the React vulnerability, coincides with the testing of new strategies by crypto-stealing drainer operators and their affiliates to evade detection and exploit crypto wallets. 

According to crypto security specialists from the Security Alliance (SEAL), drainer affiliates are now utilizing high-reputation domains for landing pages and payload hosting, re-registering previously valid domains, and implementing sophisticated fingerprinting techniques. The Security researchers claimed that the goal is to disseminate crypto-drainers, a harmful piece of JavaScript that is injected into phishing websites, and thwart security researchers.

SEAL said that evasion tactics vary among affiliates of a particular drainer family and are not consistently enforced at the drainer service level.

In a different cryptocurrency crime scenario, DeFi protocol Aevo (previously Ribbon Finance) announced on Sunday that $2.3 million had been drained from its vaults. DeFi creator Anton Cheng claimed that an updated Oracle code, which made it possible for anyone to set prices for new assets, was the primary cause of the breach.

Sign up to Bybit and start trading with $30,050 in welcome gifts

Source: https://www.cryptopolitan.com/react-flaw-triggers-crypto-wallet-drainers/

Piyasa Fırsatı
Wrapped REACT Logosu
Wrapped REACT Fiyatı(REACT)
$0.04967
$0.04967$0.04967
-4.84%
USD
Wrapped REACT (REACT) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Unstoppable: Why No Public Company Can Ever Catch MicroStrategy’s Massive Bitcoin Holdings

Unstoppable: Why No Public Company Can Ever Catch MicroStrategy’s Massive Bitcoin Holdings

BitcoinWorld Unstoppable: Why No Public Company Can Ever Catch MicroStrategy’s Massive Bitcoin Holdings Imagine trying to build a mountain of gold, only to discover
Paylaş
bitcoinworld2025/12/17 14:30
Eric Trump Says Banks Tried to Shut Him Out – Turns to Bitcoin Instead

Eric Trump Says Banks Tried to Shut Him Out – Turns to Bitcoin Instead

The post Eric Trump Says Banks Tried to Shut Him Out – Turns to Bitcoin Instead appeared on BitcoinEthereumNews.com. Bitcoin 18 September 2025 | 10:05 Eric Trump, co-founder of American Bitcoin and son of U.S. President Donald Trump, has revealed that he holds a significant personal stake in the crypto company and has no intention of selling. Trump said his ownership amounts to roughly 7.5% of shares and emphasized that both he and the board are committed to keeping their holdings locked in for the long term. According to Trump, the move reflects not only loyalty to the firm but also resistance to pressure from traditional financial institutions. He claimed that major U.S. banks have repeatedly tried to restrict his access to financial services, including efforts by Capital One, JPMorgan, and Bank of America. “They tried to shut us out of the system,” he said, describing the experience as the turning point that convinced him of crypto’s advantages. Trump argued that blockchain-based systems allow transactions to be handled “faster, cheaper, and more transparently” than legacy banking. He framed his support for American Bitcoin as both a business decision and a statement against what he called an ongoing “de-banking” campaign targeting the Trump Organization and its affiliates. By underscoring his commitment, Trump signaled that he views cryptocurrency not just as a financial instrument but as a defense against the limitations of traditional finance. His comments also echo a broader narrative that digital assets are becoming an alternative for those who feel sidelined by conventional institutions. The information provided in this article is for educational purposes only and does not constitute financial, investment, or trading advice. Coindoo.com does not endorse or recommend any specific investment strategy or cryptocurrency. Always conduct your own research and consult with a licensed financial advisor before making any investment decisions. Author Alex is an experienced financial journalist and cryptocurrency enthusiast. With over 8 years of experience…
Paylaş
BitcoinEthereumNews2025/09/18 15:08
How Crypto Could Reshape Finance, AI, and Privacy by 2026: A16z Crypto

How Crypto Could Reshape Finance, AI, and Privacy by 2026: A16z Crypto

The post How Crypto Could Reshape Finance, AI, and Privacy by 2026: A16z Crypto appeared on BitcoinEthereumNews.com. From stablecoin payments to AI-driven agents
Paylaş
BitcoinEthereumNews2025/12/17 14:38