Poisoned dependency hijacks token A-linked agent runtime, attempt to drain full wallet blocked by Ledger rejection

AI Market Summary
A security bulletin described a poisoned dependency that hijacked an agent runtime and attempted to initiate a full-wallet transfer, which the agent itself did not detect. The attempted theft was blocked because a Ledger hardware signer independently displayed the true recipient and amount, leading the user to reject the signature. No funds moved. The incident underscores supply-chain risk in crypto tooling and validates hardware signers as an effective last-line control.
Impact level
● Low
Affected assets
BTC/USDT-0.92%
AI Insight · BTC/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A technical bulletin said an agent runtime tied to a crypto asset (Token A) was hijacked via a malicious dependency package that attempted to transfer out an entire wallet balance. The agent itself did not detect anything abnormal. The user’s Ledger hardware signer independently decoded the transaction and displayed the real recipient address and amount, prompting the user to reject the signature. No funds were moved.