The post This new React bug can drain your wallets if not caught appeared on BitcoinEthereumNews.com. A critical vulnerability in React Server Components is beingThe post This new React bug can drain your wallets if not caught appeared on BitcoinEthereumNews.com. A critical vulnerability in React Server Components is being

This new React bug can drain your wallets if not caught

A critical vulnerability in React Server Components is being actively exploited by multiple threat groups, putting thousands of websites — including crypto platforms — at immediate risk with users possibly seeing all their assets drained, if impacted.

The flaw, tracked as CVE-2025-55182 and nicknamed React2Shell, allows attackers to execute code remotely on affected servers without authentication. React’s maintainers disclosed the issue on Dec. 3 and assigned it the highest possible severity score.

Shortly after disclosure, GTIG observed widespread exploitation by both financially motivated criminals and suspected state-backed hacking groups, targeting unpatched React and Next.js applications across cloud environments.

Loading…

What the vulnerability does

React Server Components are used to run parts of a web application directly on a server instead of in a user’s browser. The vulnerability stems from how React decodes incoming requests to these server-side functions.

In simple terms, attackers can send a specially crafted web request that tricks the server into running arbitrary commands, or effectively handing over control of the system to the attacker.

The bug affects React versions 19.0 through 19.2.0, including packages used by popular frameworks such as Next.js. Merely having the vulnerable packages installed is often enough to allow exploitation.

How attackers are using it

The Google Threat Intelligence Group (GTIG) documented multiple active campaigns using the flaw to deploy malware, backdoors and crypto-mining software.

Some attackers began exploiting the flaw within days of disclosure to install Monero mining software. These attacks quietly consume server resources and electricity, generating profits for attackers while degrading system performance for victims.

Crypto platforms rely heavily on modern JavaScript frameworks such as React and Next.js, often handling wallet interactions, transaction signing and permit approvals through front-end code.

If a website is compromised, attackers can inject malicious scripts that intercept wallet interactions or redirect transactions to their own wallets— even if the underlying blockchain protocol remains secure.

That makes front-end vulnerabilities particularly dangerous for users who sign transactions through browser wallets.

Source: https://www.coindesk.com/tech/2025/12/16/new-react-bug-that-can-drain-all-your-tokens-is-impacting-thousands-of-websites

Market Opportunity
Wrapped REACT Logo
Wrapped REACT Price(REACT)
$0.0507
$0.0507$0.0507
-2.50%
USD
Wrapped REACT (REACT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Samsung To Unveil New AI-Connected Living Lineup at CES 2026

Samsung To Unveil New AI-Connected Living Lineup at CES 2026

Company introduces AI-powered appliances designed to deliver smarter living by enhancing fabric care, air conditioning and cleaning Highlighted models include upgraded
Share
AI Journal2025/12/18 09:16
XRP ETF Inflows Hit $8.54M as Institutional Exposure Rises to $1.16B

XRP ETF Inflows Hit $8.54M as Institutional Exposure Rises to $1.16B

XRP is currently trading at $1.86, consolidating near a key support zone while momentum remains weak. Institutional inflows into XRP-ETFs remain positive. Flow–
Share
Tronweekly2025/12/18 09:00
Best Crypto to Buy as ChatGPT Predicts Bitcoin Will Explode After Rate Cuts

Best Crypto to Buy as ChatGPT Predicts Bitcoin Will Explode After Rate Cuts

The post Best Crypto to Buy as ChatGPT Predicts Bitcoin Will Explode After Rate Cuts appeared on BitcoinEthereumNews.com. Best Crypto to Buy as ChatGPT Predicts Bitcoin Will Explode After Rate Cuts Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Aidan Weeks, a Master’s graduate in Mechanical Engineering, has thrived as a content writer for over four years. Specializing in crypto, tech, engineering, AI, and B2B sectors, Aidan adeptly crafts web copy, blog posts, buying guides, manuals, product pages, and more, making complex concepts accessible and engaging. His transition from academia to full-time writing reflects his passion for bridging technical expertise with clear, informative content. Since joining Bitcoinist, Aidan has written extensively about DeFi, dApps, AI, and meme coins, solidifying his grasp on emerging blockchain technologies. An early adopter, he began investing in Solana in 2020, further deepening his insights into crypto markets and innovation. Today, he combines hands-on experience with a sharp editorial instinct to help readers cut through hype, spot real trends, and make sense of a fast-moving space. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/best-crypto-to-buy-chatgpt-bitcoin-rate-cuts/
Share
BitcoinEthereumNews2025/09/19 01:15