Beware! North Korean hackers have infiltrated the Waves Wallet codebase and may steal user Private Keys.

[Coin World] Coin World reported on June 19 that a North Korean developer gained elevated access to the Keeper-Wallet code repository of Waves Protocol. The account “AhegaoXXX” has been pushing updates to the dormant code repository since May 2025, and this account has been confirmed to be linked to a North Korean IT outsourcing organization. Code review found that one submission added functionality to send wallet logs and runtime errors to an external database, potentially stealing the mnemonic phrase and Private Key. Although this branch has not been merged, the attacker has published six long-unupdated malicious NPM packages by controlling the account of former Waves engineer Maxim Smolyakov. The security report points out that this incident shows North Korean hackers have shifted from ordinary outsourcing infiltration to direct control of the code repository. It is recommended that the development team strengthen Supply Chain defenses, including auditing contributor permissions, cleaning up dormant accounts, and monitoring repository redirections. Currently, the affected software’s download volume is low, but Waves users updating the Keeper-Wallet are at risk of credential leakage.

WAVES0,04%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)