Phantom is not at risk. We have confirmed that Phantom does not use vulnerable versions of any affected packages.
We implement multiple measures to mitigate this attack, including:
- Strict version locking for all dependencies to prevent automatic updates of potentially compromised packages
- Mandatory security reviews of all package upgrades before integration
- Multi-layer dependency scanning and vulnerability monitoring
- Isolated build environments with integrity verification
We take the security of our users and their funds very seriously and will continue to invest in our security practices to protect them from evolving threats like this. https://t.co/ZPPUroKieR