← Back to Glossary

Supply-Chain Attack

A supply-chain attack compromises software or hardware not by attacking the end user directly but by corrupting something upstream: a code library, a build server, an update mechanism, or a device while it is in transit. The victim installs or receives a product that was already poisoned before it arrived.

Why it matters

Bitcoin users are prime targets because stolen coins are irreversible. In 2018, the widely used JavaScript library event-stream was handed to a volunteer maintainer who inserted code designed to drain wallets from users of the Copay bitcoin app. In December 2023, a compromised developer account let attackers poison Ledger's Connect Kit library, redirecting roughly $600,000 from users of connected crypto applications within hours. Physical devices are exposed too, which is why hardware wallet makers use tamper-evident packaging, secure-element attestation, and warnings never to buy devices secondhand.

Defenses include reproducible builds, which let independent parties confirm that published binaries match the public source code, signature verification of downloads, and multivendor setups where no single manufacturer's compromise is fatal.

In the gold vs bitcoin debate

Gold has its own supply-chain attacks: gold-plated tungsten bars have periodically surfaced, including in documented cases at refiners and vaults, and detecting them requires assay equipment. The difference lies in verification cost. Authenticating gold at scale needs specialists and machinery, while authenticating bitcoin software and transactions is a computation anyone can run. Both assets teach the same lesson, that bearer instruments concentrate risk at the point of receipt, so verification is not optional.

Ready to convert your gold to Bitcoin?

Get Your Free Kit →