NPM Supply Chain Attack Targets Crypto Users with 2B+ Downloads

🚨 2B downloads compromised

By PAID NETWORK
Sep 11, 2025, 4:20 PM
twitter

A major supply chain attack infiltrated NPM packages with over 2 billion weekly downloads, specifically targeting crypto users.​ The malicious code:

  • Swaps wallet addresses with look-alikes
  • Alters transactions right before signing
  • Silently drains funds from compromised wallets

Ledger's CTO amplified warnings that millions of wallets were potentially exposed.​ The attack highlights how dependency risk creates massive blast radius vulnerabilities.​

Key Security Recommendations:

  • Use hardware-verified signing for large transactions
  • Keep keys offline and avoid hot signing
  • Verify addresses on device before confirming

NGRAVE offers a solution as the only EAL7-certified hardware wallet that operates fully air-gapped.​ Keys never touch the internet, and every transaction is screened on-device.​

PAID Network Partnership: Community members can invest in NGRAVE's equity round at a $30M valuation cap - 15% cheaper than institutional investors.​ The deal includes 7% yearly interest and converts within 24 months.​

Investment Perks:

  • $1k+: 10% wallet discount
  • $10k+: Free flagship wallet
  • Every $500 enters lottery

Learn more about the equity deal

Sources

1/ PAID community gets exclusive access to NGRAVE - the world’s most secure hardware wallet, already trusted to protect $1.6B+ in digital assets. Backed by Mechanism, Woodstock, Morningstar Ventures, IMEC, and a top-5 global asset manager. Unlike Ledger or Trezor,

Image
51
Reply

⏳ Bluwhale raise closes Monday Bluwhale = Web3’s first two-sided intelligence marketplace: • Targeting across 37 chains • Users earn for data • Privacy via federated learning Deal highlights: • Equity at $30M (70% discount to $100M round) • 1:1 BLUAI token airdrop •

Image
19
Reply

Congrats - Bluwhale has officially hit its soft cap, the first hybrid raise on PAID! Closes today at 20:00 UTC, less than 10h left to join. Deal perks: • Equity at $30M valuation (70% discount vs $100M round) • Equivalent BLUAI token airdrop bonus • 0% carry fee to celebrate

Image
25
Reply

Most investment funds take 20% carry while you keep only 80% of potential profits. At PAID, Diamond stakers (375k $PAID) pay 0% carry and keep 100%. For Bluwhale’s hybrid raise, everyone gets Diamond benefits: → 0% carry fees → $30M valuation (70% discount vs $100M round) →

Image
24
Reply

The deal is live → paidnetwork.com/equity/bluwhale Equity + tokens at a 70% discount to @bluwhaleai’s $100M round with 0% carry fees. Opportunities like this don’t repeat. Missed the registration window? Open a ticket and our team will help you join → help.paidnetwork.com/support/ticket…

PAID
PAID
@paid_network

1/ Web3 has a broken data economy. Companies burn treasuries on blind airdrops hitting bots and dead wallets. Meanwhile, tech giants like Meta and Google extract billions from user data while users get nothing. Both sides lose. Here's how @bluwhaleai fixes it 🧵

Image
30
Reply

Only 24 hours left before the Bluwhale raise closes

PAID
PAID
@paid_network

Registration is mandatory to access the @bluwhaleai deal. Here’s why Bluwhale is a once-in-a-lifetime shot: 🐋 70% discount vs. current $100M round 🐋 Equity + token airdrop (12 m cliff, 36 m vest) 🐋 Promotional 0% carry fee - keep all your upside 🐋 Backers: SBI Holdings,

27
Reply

You can own equity in NGRAVE via PAID, but why NGRAVE? 🤔 In this video, Justin our General Manager explains NGRAVE'S superior offering: 1️⃣Worlds most secure wallet - EAL-7 2️⃣Staking/swaps directly in wallet 3️⃣4.6 star rating 4️⃣Already protects $1.6B in assets Make sure to

17
Reply
Read more about PAID NETWORK

ONCHAIN FM Returns with Kaia Chain, TON Blockchain, and XNET Mobile

**ONCHAIN FM** is back this week featuring guests from **Kaia Chain**, **TON Blockchain**, and **XNET Mobile**. The show will explore: - Macro economic events - Their impact on the crypto economy - Insights from leading blockchain projects **Streaming exclusively on X** - your seat is already reserved for this discussion on market dynamics and crypto trends.

Pascal Protocol Token Now Live on Ethereum

Pascal Protocol Token Now Live on Ethereum

**Pascal Protocol (PASC) is now available for trading** following its successful flash raise on PAID Network. **Key Details:** - Claim now open on [PAID Network](https://www.paidnetwork.com/deals/pascalprotocol) - **50% tokens unlocked** at launch, remainder vests linearly over 6 months - Switch to **Ethereum chain** before claiming - Token contract: `0x65d6ae56f6e4f3aa7C4249C4023698104C4AB5F4` **Immediate Benefits:** - **Staking enabled** with 1535% APY rewards - Earn additional **Jetstream Points** - Trading pools active on [DEXTools](https://www.dextools.io/app/en/ether/pair-explorer/0x67c0f6c452831efa354c0ed379392b42eeff246d) **User Protection Active:** Participants have 24 hours to claim tokens with protection against downside risk. Pascal Protocol provides institutional-grade DeFi clearing infrastructure, already generating revenue through its Jetstream platform with $4M daily trading volume.

Pascal Protocol TGE Delayed

Pascal Protocol's Token Generation Event (TGE) has been **postponed until 14:00 UTC** today. This marks the second delay for the project, following a previous 30-minute postponement of their Flash Raise event. The team is asking for community patience as they finalize preparations for the token launch.

Pascal Clearing Hosts Live AMA on TGE and DeFi Infrastructure

**Pascal Clearing** held a live AMA discussing their upcoming **Token Generation Event (TGE)** and their mission to build the next clearing engine for DeFi. Key discussion points included: - Their **value proposition** for the DeFi ecosystem - Technical details about their **clearing engine infrastructure** - Timeline and details surrounding their **TGE launch** - How they plan to **differentiate** from existing DeFi clearing solutions The AMA provided insights into Pascal's approach to solving **settlement and clearing challenges** in decentralized finance, positioning themselves as infrastructure for the next generation of DeFi protocols.

Marketplaces