CVE-2025-29774 is a signature verification flaw in the Node.js xml-crypto library that affects versions prior to 6.0.1, 3.2.1, and 2.1.6. The vulnerability allows a valid signed XML document to be modified in a way that still passes signature verification, causing applications to trust attacker-altered content. The issue affects systems that use xml-crypto to validate signed XML for security-sensitive decisions such as SAML assertions, identity attributes, or access-control data. Available advisory material indicates the flaw is related to improper verification of XML signatures and has been described as involving unsafe handling of signature structures, including cases with multiple SignedInfo references or nodes, resulting in verification of content that does not fully correspond to the data later consumed by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository demonstrates a proof-of-concept exploit for CVE-2025-29774, a vulnerability in Bitcoin's SIGHASH_SINGLE signature handling. The main file is a Jupyter notebook that automates the process of downloading a toolset from 'darkai.ru', extracting it, and using a binary ('darkai') to craft and serialize Bitcoin transactions that exploit the SIGHASH_SINGLE bug. The exploit shows how an attacker can forge digital signatures on Bitcoin transactions, potentially allowing unauthorized spending. The repository includes a logo SVG and an author contact file, but the core exploit logic is in the notebook, which combines shell commands and Python code to demonstrate the attack. No direct network exploitation is performed; the attack is local and requires the attacker to craft and submit malicious transactions to a vulnerable Bitcoin implementation.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A purported vulnerability referenced under multiple names in the content, associated with signature handling and secret disclosure/logging issues in Bitcoin-related contexts.
The content describes CVE-2025-29774 as a critical signature verification flaw in the xml-crypto Node.js library that allows signed XML documents to be modified while still passing signature verification. The article also conflates it with a so-called 'Phantom Signature Attack' and ties it to Bitcoin payment workflows.
Referenced only in related/promotional content as part of another attack write-up; no substantive vulnerability details are provided in the main content.
A CVE mentioned only in related/reference material, associated in the content with Bitcoin signature forgery or secret disclosure themed attack names, but without substantive primary discussion.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.