Need help? Support
BITCOIN
Tether Dominance USDT.D

Which protocols were hacked this week?

Published Updated 356 words 2 min read

TLDR

This weeks confirmed incidents include the ZEROBASE protocols front-end compromise and a broader wave of wallet-drainer attacks exploiting a critical React vulnerability.

  1. ZEROBASE (BNB Chain): front-end hacked on 12 Dec, losses over $240,000%%CKPROTECTED2%% affecting ~270 users per a security notice.
  2. Multiple sites: attackers weaponized React CVE-2025-55182 to inject wallet drainers, per a security update.
  3. 0G Foundation: targeted in a vulnerability-driven attack per an incident summary.

Deep Dive

1. ZEROBASE Details

ZEROBASEs user interface was compromised on 12 Dec, with more than $240,000%%CKPROTECTED1%% stolen and roughly 270%%CKPROTECTED3%% users impacted. The team had flagged impersonation and phishing contracts shortly before the exploit, highlighting the risk around approvals on spoofed interfaces. See the notice above.

What this means

If you interacted with ZEROBASE around 1213 Dec (UTC), review approvals and revoke suspicious allowances. Use only official links and confirm contract addresses before signing.

2. React Supply Chain Attacks

A critical React Server Components RCE (CVE-2025-55182) enabled remote code execution and wallet-drainer script injection across legitimate crypto sites. Developers and teams were urged to patch React/Next.js immediately and audit front-end assets for unfamiliar hosts per a security update. Industry coverage corroborated a surge in wallet drainers exploiting the flaw and urged caution around permit signatures in pop-ups and rewards flows per a separate report.

What this means

Even trusted front-ends can be compromised. Avoid signing permit or token approval prompts unless you initiated them from a verified link, and consider a browser wallet that shows clear approval scopes.

3. 0G Foundation Incident

An industry roundup indicated 0G Foundation was targeted in an attack exploiting a vulnerability, underscoring how framework-level flaws can ripple into protocol front-ends. See the incident summary above.

What this means

Projects relying on shared web stacks are exposed to cross-cutting exploits. If you use 0G-adjacent apps, monitor official channels and rotate credentials where appropriate.

Conclusion

The weeks hacks were concentrated in two areas: a targeted protocol UI compromise (ZEROBASE) and a broad front-end supply chain risk via the React RCE. The causal thread is clear: when attackers gain the ability to inject code into real interfaces, user approvals become the attack vector. Practical mitigations are to verify official URLs, minimize blanket approvals, and revoke suspicious allowances promptly.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top