Tech Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail The Protocol: Bug that can drain all your token Tech Share Share this article Copy linkX (Twitter)LinkedInFacebookEmail The Protocol: Bug that can drain all your token

The Protocol: Bug that can drain all your tokens impacting 'thousands' of sites

12 min read
Share
Share this article
Copy linkX (Twitter)LinkedInFacebookEmail

The Protocol: Bug that can drain all your tokens impacting 'thousands' of sites

Also: Ripple news, Aave protocol debate, and pudgy penguins takeover

By Margaux Nijkerk|Edited by Jamie Crawley
Dec 17, 2025, 4:20 p.m.

What to know:

This article is featured in the latest issue of The Protocol, our weekly newsletter exploring the tech behind crypto, one block at a time. Sign up here to get it in your inbox every Wednesday.

Welcome to The Protocol, CoinDesk's weekly wrap of the most important stories in cryptocurrency tech development. I’m Margaux Nijkerk, a reporter at CoinDesk.

In this issue:

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters
Sign me up
  • New React bug that can drain all your tokens is impacting 'thousands' of websites
  • Ripple Expands $1.3B RLUSD Stablecoin to Ethereum L2s via Wormhole in Multichain Push
  • Aave DAO Pushes Back as Interface Fees Shift Away From Treasury
  • NFT Project Pudgy Penguins Takes Over Las Vegas Sphere in Holiday Campaign

Network News

BUG THAT COULD DRAIN WALLET AFFECTS THOUSANDS OF WEBSITES: A critical vulnerability in React Server Components is being actively exploited by multiple threat groups, putting thousands of websites — including crypto platforms — at immediate risk with users possibly seeing all their assets drained, if impacted. The flaw, tracked as CVE-2025-55182 and nicknamed React2Shell, allows attackers to execute code remotely on affected servers without authentication. React’s maintainers disclosed the issue on Dec. 3 and assigned it the highest possible severity score. Shortly after disclosure, GTIG observed widespread exploitation by both financially motivated criminals and suspected state-backed hacking groups, targeting unpatched React and Next.js applications across cloud environments. React Server Components are used to run parts of a web application directly on a server instead of in a user’s browser. The vulnerability stems from how React decodes incoming requests to these server-side functions. In simple terms, attackers can send a specially crafted web request that tricks the server into running arbitrary commands, or effectively handing over control of the system to the attacker. The bug affects React versions 19.0 through 19.2.0, including packages used by popular frameworks such as Next.js. Merely having the vulnerable packages installed is often enough to allow exploitation.— Shaurya Malwa Read more.

RIPPLE COMING TO ETH L2S: Ripple, the payments-focused blockchain firm closely related to the XRP Ledger (XRP), is taking its U.S. dollar-backed stablecoin to Ethereum layer-2 (L2) blockchains including Optimism, Coinbase's Base, Kraken's Ink and Uniswap's Unichain in a push to embed the $1.3 billion token deeper into the multichain ecosystem. The company said it is starting with a test phase ahead of a wider rollout expected next year, pending regulatory approval by the New York Department of Financial Services (NYDFS). The pilot integrates Wormhole’s Native Token Transfers (NTT) standard, which allows RLUSD to move natively across chains without wrapping or synthetic assets. This helps maintain liquidity and regulatory control while supporting a range of decentralized finance (DeFi) use cases across networks optimized for speed and lower costs. Stablecoins are rapidly growing as a key piece of digital-finance plumbing connecting traditional finance and the crypto economy. They are a $300 billion class of cryptocurrencies, with prices pegged to fiat money like the U.S. dollar. — Krisztian Sandor Read more.

AAVE PROTOCOL INTERFACE DEBATE INTENSIFIES: A debate inside Aave’s DAO is raising questions about who controls the protocol’s interface and who benefits financially from it. The issue surfaced after Aave Labs integrated decentralized exchange aggregator CoWSwap into the app.aave.com interface earlier this month, replacing earlier Paraswap routing used for collateral swaps. While the change was framed as a user-experience upgrade offering improved execution and MEV protection, delegates later flagged that swap-related fees were no longer flowing to the Aave DAO treasury. An open letter from Orbit delegate EzR3aL argued that the integration introduced front-end fees of roughly 15 to 25 basis points that accrue to an external recipient rather than the DAO. On-chain data cited in the post showed weekly distributions of ether tied to CoWSwap’s partner-fee mechanism across multiple networks, potentially amounting to millions of dollars annually. That surplus has since declined as routing shifted to CoWSwap’s batch-auction model, which prioritizes execution certainty over price improvement. But at the center of the debate is a distinction Aave Labs says has always existed: the protocol versus the product. In a forum reply, Aave Labs said the interface is operated, funded and maintained independently from the protocol governed by the DAO. Under this model, the DAO controls on-chain parameters, interest rates and protocol-level fees, while Labs retains discretion over optional, application-level features such as swap routing and interface monetization. “Any monetization applies only to accessory features,” Aave Labs wrote, arguing that this separation preserves protocol neutrality and avoids centralizing economic control at the base layer. Critics, however, say the practical reality has been different. Marc Zeller of the Aave Chan Initiative (ACI) said there had been a long-standing expectation that monetization tied to the aave.com frontend — including swap surplus and flash-loan-assisted execution — would benefit the DAO, especially given that the brand, governance legitimacy and much of the underlying development were funded by tokenholders. — Shaurya Malwa Read more.

PUDGY PENGUINS TAKE OVER VEGAS: Once a breakout non-fungible token (NFT) project during the 2021 crypto boom, Pudgy Penguins is turning to real-world visibility with a high-profile ad placement at the Las Vegas Sphere during Christmas week. Only a few crypto-related brands have secured ad space at the Sphere, a massive LED-covered venue known for its immersive displays and performances by acts like U2 and the Eagles. A bitcoin-focused activation ran in July, but other examples have been rare. Pudgy Penguins’ ad will run for several days starting December 24 and will include multiple animated segments, according to a person familiar with the deal. The brand spent roughly $500,000 on the placement — standard for a run at the Sphere. “It’s sort of showing that a crypto project can exceed and go out of crypto, touch the hearts and minds of everyday consumers,” Vedant Mangaldas, chief of strategy and brand at Pudgy Penguins, told CoinDesk. He said that the deal was made possible because the project has a “real business” behind it. – Helene Braun Read more.


In Other News

  • Securitize will offer what it calls the first fully compliant onchain trading platform for real public stocks in early 2026, blurring the lines between traditional markets and Web3 infrastructure. The company’s system allows investors to directly own tokenized shares of public companies, issued and recorded onchain, and tradable through a blockchain-based interface, according to an announcement. Unlike synthetic token models that track stock prices via offshore entities or derivatives, Securitize’s approach offers full legal ownership. Each share is issued by the company itself and logged on its official cap table, the firm said. “This is not a synthetic price tracker or an IOU against a custodian,” Securitize wrote in its announcement. “These are real, regulated shares: issued onchain, recorded directly on the issuer’s cap table, and tradable through a familiar Web3 swap-style experience.” That means token holders get real shareholder rights, including dividends and voting privileges, and their assets sit under self-custody, with no middlemen rehypothecating shares behind the scenes. The assets are, nevertheless, permissioned and can only be transferred between compliant, whitelisted wallets. — Francesco Rodrigues Read more.
  • Credit card giant Visa (V) is launching USDC settlement in the United States, letting issuer and acquirer partners settle obligations to the card network in Circle’s dollar-pegged stablecoin. The move marks the U.S. phase of a stablecoin settlement program that has reached a $3.5 billion annualized run rate as of Nov. 30, according to a Visa press release. The new option is meant to give banks and fintechs near-instant funds movement, seven-day-a-week settlement and more predictable liquidity around weekends and holidays, while keeping the consumer card experience unchanged. — Will Canny Read more.

Regulatory and Policy

  • U.S. Senator Elizabeth Warren has asked for another U.S. national-security probe into a corner of the crypto sector, specifying concerns with PancakeSwap, a decentralized exchange she flagged as trying to amplify coins issued by President Donald Trump-connected World Liberty Financial Inc. She said the exchange, which operates across several blockchains and is a major protocol on Binance's chain, should be reviewed for connection to "any improper political influence by the Trump Administration on enforcement decisions," Warren said in a Monday letter to Treasury Secretary Scott Bessent and Attorney General Pam Bondi, asking for them to look into it, echoing a similar request she was involved with last month regarding WLFI. “As Congress considers crypto market structure legislation — including rules to prevent terrorists, criminals, and rogue states from exploiting decentralized finance (DeFi) to fund their activities — it is critical to understand whether you are seriously investigating these risks,” wrote Warren, who is the ranking Democrat on the Senate Banking Committee that must mark up the legislation and approve it before the wider Senate can take a vote. — Jesse Hamilton Read more.
  • The U.S. Federal Deposit Insurance Corp. has rolled out the first official rule proposal stemming from the new law governing stablecoin issuers, with its board voting to open a 60-day public comment period on its system for handling applications from its regulated banks looking to issue stablecoins from subsidiaries. The agency — led by Acting Chairman Travis Hill, who is also President Donald Trump's nominee for the permanent seat — will gather comments and review them before it can release a final rule. The Tuesday proposal, approved by all three members of the shorthanded board, would establish the procedures for accepting applications, reviewing them under a 120-day approval window and offering an appeal process for those rejected. "Under the proposal, the FDIC would adopt a tailored application process that would enable the FDIC to evaluate the safety and soundness of an applicant’s proposed activities based on the statutory factors while minimizing the regulatory burden on applicants," said Hill, whose nomination could be confirmed as soon as this week by the Senate. The Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act was the first major crypto law approved by Congress, and it set out a complex array of regulators for companies wishing to issue stablecoins, the dollar-tied tokens vital to transactions in the digital assets sector. For insured depository institutions, the FDIC is the assigned regulator. — Jesse Hamilton Read more.

Calendar

  • Feb. 10-12, 2026: Consensus, Hong Kong
  • Feb. 17-21, 2026: EthDenver, Denver
  • Mar. 30-Apr. 2, 2026: EthCC, Cannes
  • Apr.15-16, 2026: Paris Blockchain Week, Paris
  • May 5-7, 2026: Consensus, Miami
NewslettersThe ProtocolBugAaveRipplePudgy Penguins

More For You

Protocol Research: GoPlus Security

Commissioned byGoPlus

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
View Full Report

More For You

Uniform Labs’ Multiliquid targets structural gap in $35 billion tokenized asset market

The new protocol offers instant swaps between tokenized money market funds and stablecoins as regulators scrutinize yield-bearing stablecoin models.

What to know:

  • Uniform Labs has launched Multiliquid, a protocol for instant, 24/7 swaps between tokenized money market funds, other RWAs and stablecoins.
  • The launch comes as the GENIUS Act tightens rules around interest on dollar-backed stablecoins, pushing institutions toward regulated yield-bearing assets.
  • Multiliquid is pitched as a market utility layer to address structural funding and exit constraints in the $35 billion tokenized asset market.
Read full story
Latest Crypto News

Crypto industry insiders meet with key senators on market structure bill negotiation

Bitcoin tumbles back below $88,000 as gains evaporate as quickly as they formed

Robinhood looks better placed than Coinbase for prediction-market upside, Mizuho says

Macquarie sees U.S. Senate near crypto deal as market structure, GENIUS rules advance

Bitcoin shorts scramble for the exits as BTC climbs

Hut 8 and Coinbase outperform as Crypto stocks jump on bitcoin's sudden rally

Top Stories

Bitcoin tumbles back below $88,000 as gains evaporate as quickly as they formed

Wall Street giant DTCC Picks privacy focused blockchain Canton Network for tokenization

Crypto industry insiders meet with key senators on market structure bill negotiation

Memecoin boom turns into capitulation one year after $150 billion market peak

Don't call it QE — the Fed's $40 billion bill buys may not shake crypto out of slump

Bitcoin trades near key price safety net that Strategy already breached

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Cashing In On University Patents Means Giving Up On Our Innovation Future

Cashing In On University Patents Means Giving Up On Our Innovation Future

The post Cashing In On University Patents Means Giving Up On Our Innovation Future appeared on BitcoinEthereumNews.com. “It’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress,” writes Pipes. Getty Images Washington is addicted to taxing success. Now, Commerce Secretary Howard Lutnick is floating a plan to skim half the patent earnings from inventions developed at universities with federal funding. It’s being sold as a way to shore up programs like Social Security. In reality, it’s a raid on American innovation that would deliver pennies to the Treasury while kneecapping the very engine of our economic and medical progress. Yes, taxpayer dollars support early-stage research. But the real payoff comes later—in the jobs created, cures discovered, and industries launched when universities and private industry turn those discoveries into real products. By comparison, the sums at stake in patent licensing are trivial. Universities collectively earn only about $3.6 billion annually in patent income—less than the federal government spends on Social Security in a single day. Even confiscating half would barely register against a $6 trillion federal budget. And yet the damage from such a policy would be anything but trivial. The true return on taxpayer investment isn’t in licensing checks sent to Washington, but in the downstream economic activity that federally supported research unleashes. Thanks to the bipartisan Bayh-Dole Act of 1980, universities and private industry have powerful incentives to translate early-stage discoveries into real-world products. Before Bayh-Dole, the government hoarded patents from federally funded research, and fewer than 5% were ever licensed. Once universities could own and license their own inventions, innovation exploded. The result has been one of the best returns on investment in government history. Since 1996, university research has added nearly $2 trillion to U.S. industrial output, supported 6.5 million jobs, and launched more than 19,000 startups. Those companies pay…
Share
BitcoinEthereumNews2025/09/18 03:26
VectorUSA Achieves Fortinet’s Engage Preferred Services Partner Designation

VectorUSA Achieves Fortinet’s Engage Preferred Services Partner Designation

TORRANCE, Calif., Feb. 3, 2026 /PRNewswire/ — VectorUSA, a trusted technology solutions provider, specializes in delivering integrated IT, security, and infrastructure
Share
AI Journal2026/02/05 00:02
Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

The post Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto appeared on BitcoinEthereumNews.com. Advertisement &nbsp &nbsp Forward Industries, the largest publicly traded Solana treasury company, has filed a $4 billion at-the-market (ATM) equity offering program with the U.S. SEC  to raise more capital for additional SOL accumulation. Forward Strategies Doubles Down On Solana Strategy In a Wednesday press release, Forward Industries revealed that the 4 billion ATM equity offering program will allow the company to issue and sell common stock via Cantor Fitzgerald under a sales agreement dated Sept. 16, 2025. Forward said proceeds will go toward “general corporate purposes,” including the pursuit of its Solana balance sheet and purchases of income-generating assets. The sales of the shares are covered by an automatic shelf registration statement filed with the US Securities and Exchange Commission that is already effective – meaning the shares will be tradable once they’re sold. An automatic shelf registration allows certain publicly listed companies to raise capital with flexibility swiftly.  Kyle Samani, Forward’s chairman, astutely described the ATM offering as “a flexible and efficient mechanism” to raise and deploy capital for the company’s Solana strategy and bolster its balance sheet.  Advertisement &nbsp Though the maximum amount is listed as $4 billion, the firm indicated that sales may or may not occur depending on existing market conditions. “The ATM Program enhances our ability to continue scaling that position, strengthen our balance sheet, and pursue growth initiatives in alignment with our long-term vision,” Samani said. Forward Industries kicked off its Solana treasury strategy on Sept. 8. The Wednesday S-3 form follows Forward’s $1.65 billion private investment in public equity that closed last week, led by crypto heavyweights like Galaxy Digital, Jump Crypto, and Multicoin Capital. The company started deploying that capital this week, announcing it snatched up 6.8 million SOL for approximately $1.58 billion at an average price of $232…
Share
BitcoinEthereumNews2025/09/18 03:42