Vulnerability library
Security checkMarch 15, 2026

@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpm@nfid/embed

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

User sessions in the @nfid/embed SDK with Ed25519 keys are vulnerable due to a compromised private key 535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe. This exposes users to potential loss of funds on ledgers and unauthorized access to canisters they control.

Recommendation

Update the @nfid/embed package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 0.10.0, < 0.10.1-alpha.6
  • Patched version(s): 0.10.1-alpha.6

References

Could your website be exposed too?

SmartScanner can check your website for @nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 15, 2026