Loading video...

Video Failed to Load

Go Home

You MUST secure your web2 environment in order to secure your web3 environment. In this video, I show how one could steal a private key from your server using the react2shell exploit. Just by visiting your website. Update ASAP if you have not already!

11,991 views • 9 months ago •via X (Twitter)

31 Comments

0xaudron's profile picture
0xaudron9 months ago

Well this is just one portion of getting rekt. Web2 has multiple ways to compromise your infrastructure resulting in private key takeover. Will be posting our recent finding, which helped us get into infrastructure of a very known protocol where we got full control of cloud and private keys were leaked in logs.

Pamphile Roy's profile picture
Pamphile Roy9 months ago

Or just be a real web3 project instead of pretending to be one and just be a shinier web2 project.

Haris Ebrat's profile picture
Haris Ebrat9 months ago

hackers right now watching Patrick

Patrick Collins's profile picture
Patrick Collins9 months ago

Nah, this is a pretty well-documented exploit.

Mate Soos's profile picture
Mate Soos9 months ago

Yep, and it turns out that most Web3 issues stem from problems we have long identified in classical IT security. Like proper key management :)

Patrick Collins's profile picture
Patrick Collins9 months ago

Yes!!!

0xBreak's profile picture
0xBreak9 months ago

I have a wild desire to enter this private key and see what's inside.

Patrick Collins's profile picture
Patrick Collins9 months ago

@ZeroNewLif It’s the anvil default key

0xBreak's profile picture
0xBreak9 months ago

Well, it would be funny if the teacher lost the key, even though he taught us to keep them separate.

NFT_Dreww.eth's profile picture
NFT_Dreww.eth9 months ago

Literally this!!!

invoker🎮's profile picture
invoker🎮9 months ago

wild seeing exploits bridge web2 gaps straight into web3 risk

SKYLINE🥷's profile picture
SKYLINE🥷9 months ago

attack surface feels bigger.

souilos's profile picture
souilos9 months ago

Thanks for this, Web3 is nothing without Web2.

Joshua Poddoku's profile picture
Joshua Poddoku9 months ago

CRITICAL risk. One Web2 slip and Web3 keys are gone. automate checks and patch fast

VERITAS PROTOCOL's profile picture
VERITAS PROTOCOL9 months ago

The old layers always matter 💯

Tim's profile picture
Tim9 months ago

Thanks for the clarity

Jatique P's profile picture
Jatique P9 months ago

So we should all learn nextjs now as web3 devs ???

Patrick Collins's profile picture
Patrick Collins9 months ago

Noooo - just a reminder to keep your key hygiene up

Stephen Clais's profile picture
Stephen Clais9 months ago

🤔

John's profile picture
John9 months ago

❤️

Lovro | Smart Contracts & Web3's profile picture
Lovro | Smart Contracts & Web38 months ago

This is a good reminder that attack surfaces extend far beyond smart contracts.

Adarsh 🦀's profile picture
Adarsh 🦀9 months ago

do you think, rust/go based client-side apps could fix this? because any close to low-level language will be better than JS at security!

Patrick Collins's profile picture
Patrick Collins9 months ago

No, you have the same issue no matter what language you write the back end in

Adarsh 🦀's profile picture
Adarsh 🦀9 months ago

Thank You :)

Artur Inspector's profile picture
Artur Inspector9 months ago

I think we will write sites with WASM ))) daamn react is literally revealing framework

Dulce's profile picture
Dulce9 months ago

PATCH FASTTTT

💥Spartan Steve💥's profile picture
💥Spartan Steve💥9 months ago

You're absolutely right - securing that Web2 foundation is everything now. One vulnerable site visit and your Web3 assets could vanish. How often are you checking for these gaps? 🔐

Lynn's profile picture
Lynn9 months ago

react2shell sounds like a nightmare on tap

Pensar's profile picture
Pensar9 months ago

Wild times

Triny's profile picture
Triny9 months ago

This is nice 💯

Divy Raj's profile picture
Divy Raj8 months ago

thats wild gotta be more careful out there

Related Videos