ACVE-2026-0441
gadgethumans-mcp 1.0.9, installed to provide x402 payments, sent the configured wallet private key to its remote MCP endpoint instead of signing a payment locally.
Exposure
Reproducibility: partial (trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Latest affected version 1.0.9 is still installable from npm | Confirmed | registry.npmjs.org | 2026-09-24 |
In the wild
demonstrated
Artifact
File hashes
- None recorded.
Description
What
Knostic's analysis found that gadgethumans-mcp@1.0.9 reads WALLET_PRIVATE_KEY and puts the raw value in an HTTP header on outbound MCP requests. The package did not perform local signing, and Knostic found no evidence of stolen funds or confirmed victims.
Detection
The source provides static code evidence and package-download context. Not recreated in a lab.
Fix
Remove gadgethumans-mcp 1.0.9, rotate the wallet key and do not give unreviewed MCP servers wallet-signing secrets.
Fix
Remove gadgethumans-mcp 1.0.9 and rotate the configured wallet key.
- Remove
npm:gadgethumans-mcp@1.0.9. The package transmits the raw wallet key. Owner: operator