By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Tech DiffThe Tech DiffThe Tech Diff
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Reading: “Malicious Packages Drain User Wallets at dYdX Cryptocurrency Exchange”
Share
Font ResizerAa
The Tech DiffThe Tech Diff
Font ResizerAa
  • Computers
  • Phones
  • Technology
  • Wearables
Search
  • Home
  • Shop
  • Computers
  • Phones
  • Technology
  • Wearables
Follow US
  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy
© Copyright 2022. All Rights Reserved By The Tech Diff.
The Tech Diff > Blog > Technology > “Malicious Packages Drain User Wallets at dYdX Cryptocurrency Exchange”
Technology

“Malicious Packages Drain User Wallets at dYdX Cryptocurrency Exchange”

Admin
Last updated: February 9, 2026 12:28 pm
Admin
Share
“Malicious Packages Drain User Wallets at dYdX Cryptocurrency Exchange”
SHARE

Contents
Malicious Code Discovered in Open Source Packages for dYdXSeverity of the BreachdYdX: A Target for CybercriminalsThe Mechanics of the AttackProtecting Yourself from Crypto Theft

Malicious Code Discovered in Open Source Packages for dYdX

Recent research from the security firm Socket has unveiled a concerning security breach impacting the dYdX decentralized derivatives exchange. Open source packages published on the npm and PyPI repositories were compromised with malicious code designed to steal wallet credentials from dYdX developers and backend systems. In a startling claim, researchers noted that this backdoor could also extend to user devices, highlighting a significant threat to both developers and regular users.

-46% Skullcandy Crusher ANC 2: Immerse in 60H of Bass Bliss!
Headphones

Skullcandy Crusher ANC 2: Immerse in 60H of Bass Bliss!

$239.99 Original price was: $239.99.$129.99Current price is: $129.99.
Buy Now
DEWALT 2-in-1 Neckband Headphones: 60+ Hrs of Music & Calls!
Headphones

DEWALT 2-in-1 Neckband Headphones: 60+ Hrs of Music & Calls!

$79.99
Buy Now
2-Pack Adjustable Monitor Risers: Elevate Your Setup!
Computer & Accessories

2-Pack Adjustable Monitor Risers: Elevate Your Setup!

$23.99
Buy Now
-20% Belkin SoundForm Mini Kids Headphones: Fun, Durable, & Key!
Headphones

Belkin SoundForm Mini Kids Headphones: Fun, Durable, & Key!

$36.99 Original price was: $36.99.$29.59Current price is: $29.59.
Buy Now

Severity of the Breach

Socket has reported that “every application using the compromised npm versions is at risk.” This alarming statement emphasizes the direct consequences for applications reliant on the affected packages, including the potential for complete wallet compromise and irreversible cryptocurrency theft. The affected versions of the packages are:

  • npm: @dydxprotocol/v4-client-js – Versions: 3.4.1, 1.22.1, 1.15.2, 1.0.31
  • PyPI: dydx-v4-client

dYdX: A Target for Cybercriminals

dYdX has emerged as a prominent player in the decentralized trading landscape, facilitating perpetual trading across hundreds of markets. The platform boasts an impressive trading volume exceeding $1.5 trillion over its lifespan, averaging between $200 million and $540 million in daily transactions. With this level of activity, it is no wonder that cybercriminals have turned their attention to the exchange.

The Mechanics of the Attack

The embedded malware in the npm packages introduced a malicious function that activated when a wallet’s seed phrase was processed. This function stealthily exfiltrated the seed phrase and collected a fingerprint of the device being used, allowing attackers to correlate stolen credentials to track victims across multiple breaches. The data was sent to a fraudulent domain—dydx[.]priceoracle[.]site—that mimics the legitimate dYdX service (dydx[.]xyz) through typosquatting methods.

Protecting Yourself from Crypto Theft

With the ever-evolving nature of cyber threats in the cryptocurrency space, it’s crucial for users and developers to remain vigilant. Avoid using outdated or compromised packages, regularly monitor your wallet for suspicious activity, and consider employing hardware wallets for enhanced security. Awareness and proactive measures can go a long way in safeguarding your assets.

For more detailed information on this security breach, read the full article here.

Image Credit: arstechnica.com

You Might Also Like

“Apple at 50: Celebrating Half a Century of Innovation”

“Agentic AI: Understanding the Alignment Problem and Future Implications”

“Apple Protects Emails from Apps, But Not Law Enforcement”

AI Music Revolution: The Latest Innovations and Trends

“Adult Braces: Lindy West’s Memoir Sparks Polyamory Controversy”

Share This Article
Facebook Twitter Copy Link Print
Previous Article “iPad Upgrade: Apple’s Entry-Level Tablet Set for Major Revamp” “iPad Upgrade: Apple’s Entry-Level Tablet Set for Major Revamp”
Next Article Amazfit T-Rex 3 Pro: Exceptional Value at Half the Apple Watch Ultra Price Amazfit T-Rex 3 Pro: Exceptional Value at Half the Apple Watch Ultra Price
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Product categories

  • Computer & Accessories
  • Headphones
  • Laptops
  • Phones
  • Wearables

Trending Products

  • 4K Mini Body Camera: Ultimate Wearable Action Cam! 4K Mini Body Camera: Ultimate Wearable Action Cam! $65.79
  • iClever BTH20: Ultimate Kids’ Noise-Cancelling Headphones! iClever BTH20: Ultimate Kids' Noise-Cancelling Headphones! $54.99 Original price was: $54.99.$36.99Current price is: $36.99.
  • Streamlined Sound: Sony IER-EX15C USB-C In-Ears for All Devices Streamlined Sound: Sony IER-EX15C USB-C In-Ears for All Devices $29.99
  • Discover OUKITEL C62 PRO: Unlocked Powerhouse Smartphone! Discover OUKITEL C62 PRO: Unlocked Powerhouse Smartphone! $159.99 Original price was: $159.99.$151.99Current price is: $151.99.
  • Boost Productivity: Foloda Wireless 22-Key Numeric Keypad! Boost Productivity: Foloda Wireless 22-Key Numeric Keypad! $18.79 Original price was: $18.79.$16.99Current price is: $16.99.

You Might also Like

“Attie: Bluesky Introduces AI for Personalized Feed Creation”
Technology

“Attie: Bluesky Introduces AI for Personalized Feed Creation”

Admin Admin 5 Min Read
Suno Unveils v5.5: Enhanced Customization Features Take Center Stage
Technology

Suno Unveils v5.5: Enhanced Customization Features Take Center Stage

Admin Admin 4 Min Read
“OpenAI’s Restructuring: A Fundamental Contradiction Revealed”
Technology

“OpenAI’s Restructuring: A Fundamental Contradiction Revealed”

Admin Admin 4 Min Read

About Us

At The Tech Diff, we believe technology is more than just innovation—it’s a lifestyle that shapes the way we work, connect, and explore the world. Our mission is to keep readers informed, inspired, and ahead of the curve with fresh updates, expert insights, and meaningful stories from across the digital landscape.

Useful Link

  • Shop
  • About
  • Contact
  • Terms & Conditions
  • Privacy Policy

Categories

  • Computers
  • Phones
  • Technology
  • Wearables

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

We don’t spam! Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

The Tech DiffThe Tech Diff
Follow US
© Copyright 2022. All Rights Reserved By The Tech Diff.
Welcome Back!

Sign in to your account

Lost your password?