VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
Undisclosed
Root cause
Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Forensic narrative
According to Finance Feeds, hackers exploited a vulnerability in the React JavaScript library to inject code into websites that steals funds from cryptocurrency wallets, primarily targeting cryptocurrency platforms. On December 3, the React team released a patch for CVE-2025-55182, a vulnerability that allowed unauthenticated code to execute on remote computers. The React team strongly advised all affected modules to upgrade immediately to prevent further exploitation. Attack method (per SlowMist): Remote Code Execution Vulnerability. Reported loss: -.
Sourced from
slowmist
Technical record
- chain
- —
- protocol
- React
- bug_class
- unknown
- date_occurred
- 2025-12-03
- loss_usd
- —
- source_id
- sm:react::2025-12-03
Related — same bug class