Ledger CTO Warns of Massive NPM Supply Chain Attack That Swaps Crypto Addresses

Ledger CTO Warns of Massive NPM Supply Chain Attack That Swaps Crypto Addresses

N
News Editor 01
2026-07-09 03:58:16
Ledger CTO Charles Guillemet warned of a large-scale NPM supply chain attack injecting code that silently swaps cryptocurrency addresses, with over 1 billion downloads of affected packages. All chains may be at risk.
LedgerNPM supply chain attackcrypto securityaddress swapJavaScript ecosystem

Charles Guillemet, Chief Technology Officer of Ledger, issued an urgent warning on Monday regarding a massive software supply chain attack targeting NPM packages used across the JavaScript ecosystem. Attackers compromised a reputable developer's NPM account and injected malicious code that automatically replaces cryptocurrency addresses during transactions, directing funds to the attackers' wallets. Guillemet stated on X that the affected packages have been downloaded over 1 billion times, exposing a large number of developers and users.

Scope: 'Potentially All Chains' at Risk

Guillemet noted that the malicious code operates silently, swapping destination addresses on the fly. He warned that the entire JavaScript ecosystem may be compromised, and the impact could extend to potentially all blockchains. It remains unclear at this stage whether the attackers have been able to steal seed phrases from software wallets.

Recommendation: Pause Onchain Transactions, Verify Addresses

To mitigate risks, Guillemet advised users who do not rely on hardware wallets to avoid making onchain transactions for the time being. He urged everyone to carefully review transaction details before signing. For users of Ledger or other hardware wallets that offer clear signing capabilities, the threat is significantly lower due to the hardware isolation and manual verification features. 'If you are using a Ledger or other hardware wallet with clear signing, you are not at risk,' he emphasized.

Industry Reaction: One of the Largest Supply Chain Attacks

Several security firms have reported similar NPM account takeovers affecting widely used packages. This campaign is being described as one of the largest software supply chain attacks to date. The incident poses a severe threat to Web applications and decentralized apps (dApps) built on the JavaScript stack. Developers are urged to review their project dependencies immediately and update or remove any suspicious packages.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.