Wasabi Wallet, a Bitcoin wallet, had a vulnerability for nearly two years that allowed an attacker to execute commands on macOS and Linux machines. The flaw, introduced in February 2024, was fixed in March 2026. The vulnerability was related to manipulated links from CoinJoin coordinators and the 'Read more' function. An attacker could create a link that, when copied to the clipboard and clicked by the user, executed unauthorized instructions with the victim's permissions. This issue posed a significant risk, allowing access to stored information, compromising wallet data, extracting keys, installing malware, or performing other actions on the device. No mass theft of funds attributable to this flaw has been reported. The issue was documented on March 16, 2026, in report #14410 and fixed in change request #14411, which reinforced link validation. An anonymous developer made the change, although their history was deleted or altered. The incident did not compromise the Bitcoin protocol nor demonstrate a vulnerability in CoinJoin, as the problem was in the application. This case adds to other recent incidents that have raised concerns about the security of tools for managing Bitcoin.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























