/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Crypto wallet maker Ledger updates Connect Kit, saying a former employee “fell victim to a phishing attack” that let a hacker insert malicious code

Crypto wallet manufacturer Ledger has confirmed an exploit that led it to warn users to “stop using dapps” started because a former employee fell for a phishing scam.

Decrypt Stacy Elliott

Context & Ripple Effects

Ledger’s Connect Kit incident extends a security record that has included exposure of customer data and earlier questions about the security trade-offs in its seed-phrase recovery proposal. This time, the affected surface is the software connector between wallets and decentralized applications rather than the hardware wallet alone.

That distinction matters because Connect Kit sits in the transaction path: Ledger’s instruction to stop using dapps shows that a compromise of supporting software can disrupt users even when the core device remains the trust anchor.

First-order effects

  • Ledger must replace the compromised Connect Kit code and manage an immediate interruption for dapp users while it restores confidence in the integration.
  • Dapp operators using Connect Kit face a near-term choice between pausing wallet connections, updating the kit, or directing users to alternative connection flows.

Second-order effects

  • Wallet providers and dapp developers are pushed to review employee-access controls, software publishing paths, and dependency monitoring; phishing resistance becomes a product-availability issue, not only an internal-security concern.
  • The incident raises the operational value of wallet-connection alternatives and of integrations that can isolate a compromised component without requiring a broad user warning.

Third-order effects

  • If such incidents persist, wallet security will be judged across the full signing and integration stack, shifting differentiation from hardware custody claims toward auditable software supply-chain controls.
  • The pattern could deepen the crypto legitimacy gap: recurring interruptions and trust failures at wallet interfaces make mainstream adoption depend on more resilient, less opaque transaction-permission layers.

The trend: Crypto wallets are becoming security-critical permission layers whose weakest operational dependency can determine the safety and availability of the broader dapp ecosystem.

Discussion

  • @ledger @ledger on x
    FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about...
  • @ledger @ledger on x
    🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨 A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves. Your Ledger device and...
  • @ledger @ledger on x
    UPDATE: The genuine Ledger Connect Kit 1.1.8 is now fully propagated. Ledger and WalletConnect can confirm that the malicious code was deactivated. You are now safe to use your Ledger Connect Kit. Reminder that that we always encourage clear signing.
  • @coindesk @coindesk on x
    At least $484k has been stolen following an exploit to Ledger's popular Connect Kit software library. The hack comes after a Ledger employee was “phished,” and blockchain security experts say DeFi users “remain at risk.” Reporting by @oknightcrypto https://www.coindesk.com/...
  • @__bigjo @__bigjo on x
    Not up to 24hrs after I made a post on the fact that your assets can never be 100% safe as long as you're using any Non-custodial wallet. Ledger was compromised because of an ex-employee and a malicious link was placed into Ledger's connect kit leading to multiple phishing... [im…