
If you're still on [at]solana/web3.js v1 and npm audit is flagging bigint-buffer (CVE-2025-3194), here's a pure JS drop-in replacement. Zero dependencies, works in browsers, and no more "Failed to load bindings" warnings. npm overrides swap in your package.json, and you're done.
Post summary
Suggests using a pure JavaScript drop‑in replacement and npm overrides to mitigate CVE‑2025‑3194, effectively acting as a patch.
