Atomic and Exodus Wallets Hit by Malicious Package Exploit

Exodus Acquires W3C Corp for $175M, Exodus Wallets / Shutterstock.com
Exodus Acquires W3C Corp for $175MImage: Exodus Wallets / Shutterstock.com

Threat actors have launched a fresh wave of cyberattacks aimed at crypto holders, specifically targeting users of Atomic and Exodus wallets through malicious software packages uploaded to coding platforms.

Security researchers warn that the malware, embedded within commonly used npm packages like pdf-to-office, is designed to harvest private keys by manipulating local wallet files.

According to analysis by ReversingLabs, the malicious code poses as legitimate software, but once installed, it stealthily modifies the user interface of Atomic and Exodus wallets. This manipulation tricks users into sending funds to addresses controlled by the attackers, effectively rerouting transactions without detection.

This kind of software supply chain attack highlights an increasingly dangerous trend in the crypto space, where hackers infiltrate development environments to carry out exploits at the infrastructure level.

The scale of such attacks continues to grow. In the first quarter of 2025 alone, cybersecurity firm Hacken estimates that crypto-related hacks and exploits resulted in losses exceeding $2 billion. A staggering $1.4 billion of that figure came from the Bybit hack in February - currently the largest in crypto history.

Following the incident, SafeWallet - a wallet provider implicated in the breach - shared a detailed post-mortem in March 2025. Investigators revealed that hackers compromised a developer's computer and hijacked AWS session tokens to infiltrate SafeWallet’s internal systems and orchestrate the Bybit theft.

Meanwhile, another deceptive tactic gaining traction is the "address poisoning" scam. Casa's chief security officer and well-known cypherpunk Jameson Lopp recently raised concerns over this subtle yet effective exploit.

In these attacks, scammers generate wallet addresses that visually resemble those in a victim’s transaction history - typically by mimicking the first and last few characters. A small transaction is then sent to the victim to implant the fake address into their history. If the user unknowingly reuses this address, their funds are redirected to the attacker.

Cyvers, a cybersecurity firm monitoring blockchain threats, reported that address poisoning alone led to over $1.2 million in stolen crypto during March 2025.

As threat actors evolve their methods, from manipulating development tools to exploiting user habits, cybersecurity professionals are calling for heightened vigilance across all fronts of the crypto ecosystem.

Kostiantyn Tsentsura profile photo

Kostiantyn Tsentsura

Kostiantyn Tsentsura is a Content Writer at Yellow.com with over 8 years of experience in crypto, dedicating the last 4 years to writing about the industry. Based in Kyiv, he’s passionate about football, fishing, and kayaking. When he’s not tracking market trends or exploring crypto news, you’ll find him on the water—because even in crypto, sometimes it’s best to just go with the flow.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News
Atomic and Exodus Wallets Hit by Malicious Package Exploit | Yellow