BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Rust Crates Steal Ethereum, Solana Wallet Keys

Malicious Rust Packages Found on Crates.io Stealing Solana and Ethereum Wallet Keys

  • Researchers found two malicious Rust packages disguised as a popular library targeting crypto wallet keys.
  • The compromised packages, named faster_log and async_println, had over 8,400 downloads before removal.
  • These packages stole Solana and Ethereum private keys from source code and sent them to a command-and-control server.
  • The crates copied legitimate code and documentation, making them appear trustworthy to developers.
  • The Rust package registry has removed the malicious crates and preserved user logs for investigation.

Cybersecurity researchers identified two harmful Rust packages distributed on crates.io that imitated a well-known logging library to steal private crypto wallet keys. The crates, called faster_log and async_println, appeared to be legitimate software, but their true purpose was to collect Solana and Ethereum wallet keys from developers’ source code.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to Socket, a software supply chain security firm, the attacker used the aliases rustguruman and dumbnbased and published the crates on May 25, 2025. Together, these packages reached 8,424 downloads before being taken down. Security researcher Kirill Boychenko said the crates worked as logging tools but secretly searched for wallet keys and sent any found to a hardcoded web address controlled by the attacker.

“The malicious code was executed at runtime, when running or testing a project depending on them,” explained Walter Pearce from Crates.io. He added, “Notably, they did not execute any malicious code at build time. Except for their malicious payload, these crates copied the source code, features, and documentation of legitimate crates, using a similar name to them.” After a responsible disclosure, crates.io removed the packages and disabled both user accounts.

Socket described the tactic as a supply chain attack using typosquatting—where names similar to real packages deceive users. The fake packages kept all normal logging functions but added code that searched files with the .rs extension for wallet keys and uploaded them to a server hosted at mainnet.solana-rpc-pool.workers[.]dev.

Attackers also duplicated the README file and linked to the real fast_log GitHub project, making the bogus packages harder to identify. The use of a domain similar to Solana’s real Mainnet beta RPC endpoint further increased the risk of confusion.

- Advertisement -

Crates.io reported that the malicious crates did not have any dependent packages and the related GitHub accounts remain active. According to Boychenko, “A functional logger with a familiar name, copied design, and README can pass casual review, while a small routine posts private wallet keys to a threat actor-controlled C2 endpoint. Unfortunately, that is enough to reach developer laptops and CI.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Gold Crashes to 4-Month Low; Strategists Keep $5K–$6.3K Targets

Gold crashed to a four-month low of $4,098, posting its worst five-session performance since...

Baltimore sues xAI over Grok’s millions of non-consensual deepfakes

The Mayor and City Council of Baltimore have sued X Corp., xAI, and SpaceX,...

SpaceX Targets Historic $75B IPO Filing This Week

SpaceX may file for its record-breaking IPO as soon as this week, targeting a...

Ethereum Aims for Quantum Resistance by 2029

The Ethereum Foundation has launched a "Post-Quantum Ethereum" resource hub to address future quantum...

NASA Shifts Artemis to Build $20B Permanent Moon Base

NASA has shifted its Artemis program strategy, now prioritizing the construction of a permanent...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading