Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Ledger CTO Warns Users Amid Massive NPM Supply Chain Attack

Hackers hit a trusted NPM account, adding malicious code to JavaScript packages downloaded over 1B times, risking crypto projects.

Written By:
Ronak Kumar

Reviewed By:
Dhara Chavda

Last updated: September 9, 2025 12:17 PM
Published September 9, 2025 12:17 PM
Share
Last updated: September 9, 2025 12:17 PM
Published September 9, 2025 12:17 PM
Ledger CTO Warns Users Amid Massive NPM Supply Chain Attack

Ledger’s Chief Technology Officer, Charles Guillemet, issued a strong warning on Monday, urging some users to temporarily stop on-chain transactions. The alert comes after a massive supply chain attack compromised a trusted developer’s NPM account, affecting packages that have been downloaded over 1 billion times.

“There’s a large-scale supply chain attack in progress,” Guillemet said in a post on X. “If you use a hardware wallet, pay attention to every transaction before signing and you’re safe. If you don’t, refrain from making any on-chain transactions for now.”

How the Attack Works

Supply chain attacks target the software distribution process, not individual users. Here, hackers acquired the NPM account of a developer ‘qix’.

They allegedly inserted malicious code, which replaces cryptocurrency addresses automatically, deceiving users to send money to the attacker, rather than the receiver. This method is similar to tactics used by North Korean hackers to steal $1.5 billion from the crypto exchange Bybit earlier this year.

Crypto developers quickly noticed the attack. @0x_ultra shared that packages like Chalk, with over 2 billion weekly downloads, were compromised and could steal private keys.

The impacted developer verified the attack, saying that phishing emails that pretended to be NPM threatened to lock accounts of maintainers to tempt them to visit rogue websites. However, at the time of reporting, the attacker only managed to steal $498.

What Users Should Do

The compromised packages were reportedly patched around 15:15 UTC. However, websites and apps that updated dependencies recently might still be at risk. 

Further, Uniswap, Metamask, Ledger, OKX Wallet, Sui, Aave and Morpho have stated that they were “not affected” by the NPM supply chain attack.

Guillemet also reassured users that those using hardware wallets with clear signing are safe. Developers are encouraged to verify all the dependencies and make sure that they are not using the compromised versions.

This attack is being described as possibly the biggest supply chain attack in history, and it is a reminder of the increasing risks in the software ecosystem and the role of security in crypto transactions.

Also Read: SwissBorg Crypto Platform Loses $41M Solana in Major Security Breach

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Blockchain
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Ronak Kumar- Crypto Journalist at The Crypto Times
By Ronak Kumar
Follow:
Ronak Kumar is a Crypto Journalist with over 3 years of experience covering blockchain, AI, finance, and emerging digital trends. With a background in Commerce (B.Com) and a Postgraduate Diploma in Management (PGDM), he combines business insight with a clear understanding of the evolving crypto space. His reporting has been featured in major publications, with his work cited by NDTV, Hindustan Times, and Outlook India on topics like Trump Memecoin, Bhutan’s crypto mining, and Barron Trump’s digital presence.
Dhara Chavda- Crypto Research Analyst at The Crypto Times
By Dhara Chavda
Follow:
Dhara Chavda is a Content Strategist and Research Analyst with 5 years of experience in the crypto industry. She holds a Bachelor’s degree in Computer Engineering and brings a strong technical perspective to her work. Dhara specializes in DeFi, price analysis, and the core mechanics of cryptocurrencies. She also works on crypto news, including research, analysis, and assigning stories, ensuring accurate and timely coverage of key developments in the space.

Latest News

LayerZero Says “We Own That” After $292M Kelp DAO Hack, Admits Security Mistake
LayerZero Says “We Own That” After $292M Kelp DAO Hack, Admits Security Mistake
What Does Bitcoin Become in a World Questioning the Dollar?
What Does Bitcoin Become in a World Questioning the Dollar?
40+ DeFi Protocols Shut Down in 2026 Inside the $770M Hack Crisis Reshaping Crypto
40+ DeFi Protocols Shut Down in 2026: Inside the $770M Hack Crisis Reshaping Crypto
TON Leads Crypto Staking Returns as Telegram Ecosystem Expands
TON Leads Crypto Staking Returns as Telegram Ecosystem Expands
TeraWulf Earns More From AI Computing Than Bitcoin Mining in Q1
TeraWulf Earns More From AI Computing Than Bitcoin Mining in Q1

Find Us on Socials

You may also like

Stablecoins, RWAs, ETFs Fuel Crypto’s April Market Rebound: Binance

Stablecoins, RWAs, ETFs Fuel Crypto’s April Market Rebound: Binance

World Liberty Financial Launches USD1 Stablecoin Natively on Stripe-Backed Tempo L1 Blockchain

World Liberty Financial Launches USD1 Stablecoin Natively on Stripe-Backed Tempo L1 Blockchain

Switzerland Bitcoin Reserve Push Fails As Referendum Drive Ends

Switzerland Bitcoin Reserve Push Fails As Referendum Drive Ends

Taiwan Indicts TV Anchor Over USDT Linked China Spy Probe

Taiwan Indicts TV Anchor Over USDT Linked China Spy Probe

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information