Poisoned dependency hijacks token A-linked agent runtime, attempt to drain full wallet blocked by Ledger rejection
AI مارکیٹ کا خلاصہ
A security bulletin described a poisoned dependency that hijacked an agent runtime and attempted to initiate a full-wallet transfer, which the agent itself did not detect. The attempted theft was blocked because a Ledger hardware signer independently displayed the true recipient and amount, leading the user to reject the signature. No funds moved. The incident underscores supply-chain risk in crypto tooling and validates hardware signers as an effective last-line control.
اثر کی سطح
● لو
متاثرہ اثاثے
BTC/USDT-1.16%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
A technical bulletin said an agent runtime tied to a crypto asset (Token A) was hijacked via a malicious dependency package that attempted to transfer out an entire wallet balance. The agent itself did not detect anything abnormal. The user’s Ledger hardware signer independently decoded the transaction and displayed the real recipient address and amount, prompting the user to reject the signature. No funds were moved.