CIAN Security Update: We Are Safe After npm Attack

Summary

CIAN has issued a security update confirming that all of its frontend projects are safe following a recent attack that poisoned the popular npm package "error-ex." Attackers used this vulnerability to redirect MetaMask transactions to malicious addresses, but CIAN's comprehensive audits found no compromised packages in their systems. As an extra precaution, CIAN has locked all package versions, assuring users that their interfaces remain completely safe to use.

Security Update: Cian is Safe

What Happened: The npm package "error-ex" (47M weekly downloads) was poisoned by attackers. Affected websites would redirect MetaMask transactions to hacker addresses using similar-looking addresses to confuse users during signing.

Cian's Status:
- All Safe - Comprehensive audit of our 5 frontend projects found zero compromised packages (checked both direct dependencies and all upstream transitive dependencies)
- Extra Precaution - We've locked all package versions and paused updates until threats clear
Bottom Line: It is completely safe to use all Cian interfaces.

General Security Recommendations:
- Hardware wallet users: Enable clear signing and verify every address digit-by-digit
- Software wallet users: Consider avoiding on-chain transfers temporarily, or at minimum pause updates/usage of suspicious JS packages
- Developers: Immediately check dependency versions and rollback to safe versions or lock dependencies
https://x.com/CIAN_protocol/status/1965288253353025874

Security Update: Cian is Safe

What Happened: The npm package "error-ex" (47M weekly downloads) was poisoned by attackers. Affected websites would redirect MetaMask transactions to hacker addresses using similar-looking addresses to confuse users during signing.

Cian's Status:
X

8 views

The latest from CIAN

Bondify Live: Tradable Yield RWA Positions

Bondify is now live.🔥🔥 Bondify is built for the next layer of RWAfi: helping yield-bearing RWA positions become more usable, tradable, and flexible after they …

Bondify RWA Yield & Automation Coming Soon

🚀 🚀🚀Bondify is coming soon. This is a new extension of what we have been building around yield, automation, and risk-aware DeFi strategies. With Bondify, …

CIAN Hits $10M+ TVL in 24 Hours!

🚀🚀🚀**Milestone: $10,000,000+ TVL reached within 24 hours.** USDT vault **$10.05M**! USDC vault **$1.44M**! Thanks for the trust — we’ll keep shipping.🚢 @Mantle_Official @Bybit_Official **🔥Subscribe, earn, …

CIAN & Bybit Launch Mantle Vault for 7-12% APY

**🚀Launch Alert: Bybit Mantle Vault powered by CIAN 🚀** APY target 7–12%.📈 **One-click** via @Bybit_Official **On-Chain Earn → Auto-leverage** by @CIAN_protocol on @Mantle_Official. Deposit **USDC** …