Crypto Hack Alert

Crypto Hack Alert

Source: YouTube · Will Lamerton · published Sep 9, 2025 · 20:33

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

A major crypto supply chain hack has compromised npm packages, affecting users of hardware wallets by swapping crypto addresses during transactions 1:35-1:43.

Key Takeaways:
• The hack works by replacing legitimate crypto addresses with visually similar hacker addresses when users copy-paste them 2:35-2:47
• This primarily affects hardware/cold wallets like Ledger and Trezor, not necessarily centralized exchanges 3:53-4:17
• The attack exploited npm (Node Package Manager) packages with 2.6 billion weekly downloads in the developer ecosystem 4:54-5:04
• The malicious code scans for crypto addresses and swaps them in the user interface to trick people 6:19-6:26
• Users should carefully verify the full destination address before sending any crypto transactions 7:40-8:03

This incident highlights the vulnerability of software supply chains and the importance of personal responsibility in crypto security 9:45-9:49.

Sources:

  • 1:35-1:43 Introduction to the crypto supply chain hack
  • 2:35-2:47 Explanation of how the hack works
  • 3:53-4:17 Clarification that hardware wallets are primarily affected
  • 4:54-5:04 Details on npm packages and the scale of the problem
  • 6:19-6:26 How the malicious code functions
  • 7:40-8:03 Key recommendation about address verification

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hey everyone, welcome back. Good morning, good afternoon, good evening. Could be any time of day, who knows what it is. It's the It's the YouTube. So, uh I hope you're all doing really well. Um we're going to dive into um a news article which I think is really relevant. Um again, for those new to the show, firstly, give us a like, subscribe, comment, say hello. You know, we really appreciate you. would love to sort of get to start build a relationship with our community and you know get a bit of a a thing going. So really appreciate any support that uh you're able to do able to do. Obviously a like doesn't cost anything so just hit it please. Thank you. We're a new show. So join us at this early incubation period. It's like you know planting acorns so we'll see where it goes. >> Absolutely…