Home / Companies / Socket / Blog / Post Details
Content Deep Dive

2025 Blockchain and Cryptocurrency Threat Report: Malware in...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,087
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

The 2025 Blockchain and Cryptocurrency Threat Report by the Socket Threat Research Team highlights a significant rise in malware targeting the open-source supply chain of the cryptocurrency and blockchain development ecosystem. The report identifies four recurring threat classes—credential stealers, crypto drainers, cryptojackers, and clipboard hijackers—that exploit open-source package registries like npm and PyPI to compromise Web3 development environments. These threats primarily aim at blockchain developers, leveraging malicious packages to extract sensitive information, siphon funds, and mine cryptocurrencies covertly. The report notes a growing interest from financially motivated threat actors, including some nation-state groups, in expanding their campaigns beyond Ethereum and Solana to other blockchain platforms like TRON and TON. As the attack surface broadens with the convergence of Web3 and mainstream software engineering, the report stresses the need for enhanced software supply chain security practices. This includes strict validation of dependencies, disabling unnecessary lifecycle hooks in CI/CD pipelines, auditing for suspicious activities, and advancing security tools to detect sophisticated malware tactics.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.