bitcoin
Bitcoin (BITCOIN)
$89,652 0.67%
ethereum
Ethereum (ETHEREUM)
$3,152 2.54%
binancecoin
BNB (BINANCECOIN)
$887.48 0.01%
solana
Solana (SOLANA)
$132.27 0.92%
ripple
XRP (RIPPLE)
$1.99 -0.65%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000008 0.14%
pepe
Pepe (PEPE)
$0.000004 0.82%
bonk
Bonk (BONK)
$0.000009 0.68%
bitcoin
Bitcoin (BITCOIN)
$89,652 0.67%
ethereum
Ethereum (ETHEREUM)
$3,152 2.54%
binancecoin
BNB (BINANCECOIN)
$887.48 0.01%
solana
Solana (SOLANA)
$132.27 0.92%
ripple
XRP (RIPPLE)
$1.99 -0.65%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000008 0.14%
pepe
Pepe (PEPE)
$0.000004 0.82%
bonk
Bonk (BONK)
$0.000009 0.68%
bitcoin
Bitcoin (BITCOIN)
$89,652 0.67%
ethereum
Ethereum (ETHEREUM)
$3,152 2.54%
binancecoin
BNB (BINANCECOIN)
$887.48 0.01%
solana
Solana (SOLANA)
$132.27 0.92%
ripple
XRP (RIPPLE)
$1.99 -0.65%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000008 0.14%
pepe
Pepe (PEPE)
$0.000004 0.82%
bonk
Bonk (BONK)
$0.000009 0.68%
Disclosure
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
SEAL Warns Crypto Websites at Risk from Wallet Drainers and Fake Zoom Scams

Highlights:

  • SEAL warns crypto websites are at risk due to React vulnerability exploitation.
  • Wallet drainers trick users through fake pop-ups and phishing signature requests daily.
  • SEAL alerts that North Korean hackers are stealing millions via fake Zoom calls.

Cybersecurity group Security Alliance (SEAL) says more crypto drainers are appearing on websites. This is due to a flaw in the JavaScript library React. The flaw, CVE-2025-55182, allows attackers to run code without permission. They can also insert scripts that steal crypto wallets.

Advertisement

Banner

React, which is used to build web interfaces, stated on Dec. 3 that hacker Lachlan Davidson discovered the flaw. The vulnerability enables attackers to run code remotely without logging in. Hackers are now exploiting this weakness to target crypto websites and steal users’ wallets. SEAL warned that these attacks are serious. They advised that all websites should review their code for suspicious files immediately.

Websites at Risk from Hidden Wallet Drainers

The nonprofit said some websites marked as phishing targets might have been affected without a clear reason. They suggested that website owners check for CVE-2025-55182 and look at front-end scripts for hidden JavaScript or unknown files.

SEAL added that websites being blocked could have this issue. They advised reviewing code carefully before asking to remove phishing warnings. SEAL also stressed checking signature requests to make sure wallet recipients are correct. They explained that wallet drainers trick users into signing transactions using fake pop-ups or reward promises. SEAL warns that the attacks are not only on Web3 protocols. All websites could be at risk, and users should be careful when signing any permit signature.

React released a patch on Dec. 3 to fix the security flaw. The team told users of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack to update immediately to close the vulnerability. The React team said apps that do not use a server remain unaffected. They also said apps that do not use a framework, bundler, or plugin for React Server Components are safe. The patch is meant to stop attackers from adding wallet-draining code to websites. It helps protect users from losing money in unauthorized transactions.

North Korean Hackers Target Users with Fake Zoom Calls

SEAL also warned that North Korean hackers are running multiple scams every day using fake Zoom meetings. In fact, security researcher Taylor Monahan said these scams have already stolen more than $300 million from victims by tricking them into downloading malware.

According to Monahan, the scam usually begins with a message from a Telegram account that the victim knows. Attackers invite users to a Zoom call, making them believe it is a real conversation with friends or colleagues. She added that attackers often share a link before the call and mask it to look genuine.

On the call, victims may see the person and some of their partners or colleagues. Monahan explained that these videos are not deepfakes, as some reports claimed. Instead, they are real recordings taken from hacked sources or publicly available content, such as podcasts.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Advertisement

Banner

Advertisement

Banner