Vulnerabilities/

@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys

Severity:
High

Description

User sessions in the @nfid/embed SDK with Ed25519 keys are vulnerable due to a compromised private key 535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe. This exposes users to potential loss of funds on ledgers and unauthorized access to canisters they control.

Recommendation

Update the @nfid/embed package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nfid/embed
Anything's wrong? Let us know Last updated on March 15, 2026