Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

XRP Price Upside Rejected, Momentum Shifts Back to Sellers

April 15, 2026

OpenAI Rotates macOS Certificates After Axios Supply Chain Attack

April 15, 2026

Ethereum Exchange Supply Has Dropped 57% From Its Peak: Holders Refuse To Exit

April 15, 2026
Facebook X (Twitter) Instagram
Wednesday, April 15 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Upgrade to Address Web3.js Issue

December 4, 2024Updated:December 4, 2024No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Upgrade to Address Web3.js Issue
Share
Facebook Twitter LinkedIn Pinterest Email
ad

Phantom has confirmed that it has not been affected by a vulnerability found within the Solana library, i.e. Solana/web3.js.

Phantom, a pockets supplier operating on the Solana (SOL) blockchain, confirmed it’s protected after a latest vulnerability was found within the Solana/Web3.js library. In keeping with a press release posted on X, the Phantom safety staff verified that the compromised variations of the library- 1.95.6 and 1.95.7 – won’t ever be utilized of their infrastructure, assuring their customers that their platform is secured. 

anybody utilizing @solana/web3.js, variations 1.95.6 and 1.95.7 are compromised with a secret stealer leaking personal keys. for those who or your product are utilizing these variations, improve to 1.95.8 (1.95.5 is unaffected)

for those who run a service that may blacklist addresses, do your factor with…

— trent.sol (@trentdotsol) December 3, 2024

Don’t use @solana/web3.js variations 1.95.6 and 1.95.7., writes Trent.sol on his X profile.

Earlier right this moment, Trent Sol, a Solana developer, warned customers concerning the compromised library. He knowledgeable customers that these variations might put customers vulnerable to secret stealer assaults, that are able to leaking personal keys used to entry and safe wallets. Merchandise and builders utilizing the compromised variations ought to improve to model 1.95.8., urged Trent. Nevertheless, earlier variations, reminiscent of 1.95.5, stay unaffected by the problems. 

Phantom is just not impacted by this vulnerability.

Our Safety Workforce confirms that now we have by no means used the exploited variations of @solana/web3.js https://t.co/9wHZ4cnwa1

— Phantom (@phantom) December 3, 2024

Phantom acknowledges that it’s protected from solana/web3.js vulnerabilities.

Solana ecosystem addresses Web3.js vulnerability

The Solana ecosystem has been fast to reply to addressing the vulnerability. Necessary initiatives reminiscent of Drift, Phantom, and Solflare have knowledgeable their communities that they don’t seem to be affected as they both don’t put to make use of the compromised model or produce other safety measures that preserve them protected. The ecosystem’s builders and initiatives are additionally urged to test their dependencies and replace their libraries to make sure funds and information stay safe. 

Rise in vulnerabilities

Trent Sol’s disclosure of vulnerability displays a bigger problem of safety that blockchain ecosystems usually need to deal with. Forensic evaluation reveals that the damaged variations of the library held hidden instructions meant to seize and transmit personal keys to a pockets named FnvLGtucz4E1ppJHRTev6Qv4X7g8Pw6WPStHCcbAKbfx. Cloud safety researcher Christophe Tafani-Dereeper from Datadog underscored the sophistication of the backdoor at Bluesky. 

Developer Tafani-Dereeper does forensic evaluation of the solana/web3.js vulnerabilities.

Such dangers have develop into more and more widespread, as evidenced by a malicious package deal incident earlier this 12 months, reported by The Hacker Information, involving the Python Bundle Index, generally referred to as PyPl. The package deal, “solana-py“, masqueraded because the professional Solana Python API to steal Solana pockets keys and exfiltrate them to an attacker-controlled server. It additionally exploited naming similarities to trick builders, resulting in 1,122 downloads earlier than its removing.

ad
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

XRP Price Upside Rejected, Momentum Shifts Back to Sellers

April 15, 2026

Will XRP price break above the symmetrical triangle as the daily MACD turns bullish?

April 15, 2026

Bitcoin Price Chart Targets $90K As Transaction Count Hits 17-month High

April 14, 2026

Solana price forms symmetrical triangle amid MACD cross

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
XRP Price Upside Rejected, Momentum Shifts Back to Sellers
April 15, 2026
OpenAI Rotates macOS Certificates After Axios Supply Chain Attack
April 15, 2026
Ethereum Exchange Supply Has Dropped 57% From Its Peak: Holders Refuse To Exit
April 15, 2026
Will XRP price break above the symmetrical triangle as the daily MACD turns bullish?
April 15, 2026
Bitcoin Price Chart Targets $90K As Transaction Count Hits 17-month High
April 14, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.