The post This new React bug can drain your wallets if not caught appeared on BitcoinEthereumNews.com. A critical vulnerability in React Server Components is beingThe post This new React bug can drain your wallets if not caught appeared on BitcoinEthereumNews.com. A critical vulnerability in React Server Components is being

This new React bug can drain your wallets if not caught

A critical vulnerability in React Server Components is being actively exploited by multiple threat groups, putting thousands of websites — including crypto platforms — at immediate risk with users possibly seeing all their assets drained, if impacted.

The flaw, tracked as CVE-2025-55182 and nicknamed React2Shell, allows attackers to execute code remotely on affected servers without authentication. React’s maintainers disclosed the issue on Dec. 3 and assigned it the highest possible severity score.

Shortly after disclosure, GTIG observed widespread exploitation by both financially motivated criminals and suspected state-backed hacking groups, targeting unpatched React and Next.js applications across cloud environments.

Loading…

What the vulnerability does

React Server Components are used to run parts of a web application directly on a server instead of in a user’s browser. The vulnerability stems from how React decodes incoming requests to these server-side functions.

In simple terms, attackers can send a specially crafted web request that tricks the server into running arbitrary commands, or effectively handing over control of the system to the attacker.

The bug affects React versions 19.0 through 19.2.0, including packages used by popular frameworks such as Next.js. Merely having the vulnerable packages installed is often enough to allow exploitation.

How attackers are using it

The Google Threat Intelligence Group (GTIG) documented multiple active campaigns using the flaw to deploy malware, backdoors and crypto-mining software.

Some attackers began exploiting the flaw within days of disclosure to install Monero mining software. These attacks quietly consume server resources and electricity, generating profits for attackers while degrading system performance for victims.

Crypto platforms rely heavily on modern JavaScript frameworks such as React and Next.js, often handling wallet interactions, transaction signing and permit approvals through front-end code.

If a website is compromised, attackers can inject malicious scripts that intercept wallet interactions or redirect transactions to their own wallets— even if the underlying blockchain protocol remains secure.

That makes front-end vulnerabilities particularly dangerous for users who sign transactions through browser wallets.

Source: https://www.coindesk.com/tech/2025/12/16/new-react-bug-that-can-drain-all-your-tokens-is-impacting-thousands-of-websites

Piyasa Fırsatı
Wrapped REACT Logosu
Wrapped REACT Fiyatı(REACT)
$0.05014
$0.05014$0.05014
-3.94%
USD
Wrapped REACT (REACT) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Crypto ETF Floodgates Open With SEC Listing Standards. What Does It Mean For Prices?

Crypto ETF Floodgates Open With SEC Listing Standards. What Does It Mean For Prices?

The post Crypto ETF Floodgates Open With SEC Listing Standards. What Does It Mean For Prices? appeared on BitcoinEthereumNews.com. The U.S. Securities and Exchange Commission (SEC) has cleared a path for a flood of new crypto exchange-traded products to hit the market, a move analysts say could reshape how money flows into digital assets. On Wednesday, the agency approved generic listing standards for “commodity-based trust shares” across regulated exchanges Nasdaq, Cboe BZX and NYSE Arca. Read more: SEC Makes Spot Crypto ETF Listing Process Easier, Approves Grayscale’s Large-Cap Crypto Fund The new rules remove the need for each crypto ETP to undergo its own individual rule filing under Section 19(b) of the Exchange Act. Instead, an offering whose underlying assets satisfy certain objective eligibility tests — for example, if the crypto trades on a market that is a member of the Intermarket Surveillance Group (ISG), or if the underlying asset’s futures contract is listed on a CFTC-regulated designated contract market for at least six months — can be listed using these generic standards. What’s next? The regulatory shift marks a watershed for the crypto industry, removing much of the procedural drag that has historically slowed getting new crypto products to the market, analysts said. “[The] crypto ETF floodgates are about to open,” said Nate Geraci, a well-followed ETF analyst and president of NovaDius Wealth Management. “Expect an absolute deluge of new filings and launches,” he said. “You may not like it, but crypto is going mainstream via the ETF wrapper.” Matt Hougan, chief investment officer of digital asset management firm and ETF issuer Bitwise, said the SEC’s move is a “coming of age” moment for crypto. “[It’s] a signal that we’ve reached the big leagues,” he wrote. “But it’s also just the beginning.” History backs up predictions that the number of new crypto ETF launches will accelerate under the new regime. When the SEC approved generic listing standards for…
Paylaş
BitcoinEthereumNews2025/09/20 14:14
OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

PANews reported on September 17th that on-chain sleuth ZachXBT tweeted that OpenVPP ( $OVPP ) announced this week that it was collaborating with the US government to advance energy tokenization. SEC Commissioner Hester Peirce subsequently responded, stating that the company does not collaborate with or endorse any private crypto projects. The OpenVPP team subsequently hid the response. Several crypto influencers have participated in promoting the project, and the accounts involved have been questioned as typical influencer accounts.
Paylaş
PANews2025/09/17 23:58
US Senators Introduce SAFE Crypto Act to Target Rising Crypto Scams

US Senators Introduce SAFE Crypto Act to Target Rising Crypto Scams

The post US Senators Introduce SAFE Crypto Act to Target Rising Crypto Scams appeared first on Coinpedia Fintech News Crypto scams are getting faster, smarter and
Paylaş
CoinPedia2025/12/17 18:33