Crypto wallet maker Ledger updates Connect Kit, saying a former employee “fell victim to a phishing attack” that let a hacker insert malicious code
Crypto wallet manufacturer Ledger has confirmed an exploit that led it to warn users to “stop using dapps” started because a former employee fell for a phishing scam.
Decrypt Stacy Elliott
Related Coverage
- A letter from Ledger Chairman & CEO Pascal Gauthier Regarding Ledger Connect Kit Exploit Ledger
- Phishing Attack Led to Supply Chain Compromise, $600K Theft at Ledger Metacurity · Cynthia Brumfield
- Supply chain attack targeting Ledger crypto wallet leaves users hacked TechCrunch · Lorenzo Franceschi-Bicchierai
- Ledger Exploit Endangers DeFi; Sushi Says ‘Do Not Interact With ANY dApps’ CoinDesk · Oliver Knight
- Massive Ledger Security Event Impacted Numerous Crypto Apps, Industry Professional Provides Guidance for Securing Assets in Self-Custody Crowdfund Insider · Omar Faridi
- Aftermath: How The Ledger Hacker's $484k Heist Went Down Blockonomi · Oliver Dale
- Tether freezes wallet after Ledger ConnectKit hack incident Cryptopolitan · Mutuma Maxwell
- Crypto Hardware Wallet Ledger's Supply Chain Breach Results in $600,000 Theft The Hacker News
- Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code CoinDesk · Oliver Knight
- Protecting Your Crypto: Ledger's Recent Scare and Bitcoin's Resilience The Dark Side
- Ledger eliminated exploit, company's CEO comments on situation crypto.news · Anna Kharton
- Ledger Declares Users are ‘Safe’ to Use Connect Kit, Following Malicious Attack BeInCrypto · Ciaran Lyons
- Ledger Discloses Update and Timeline of the Recent Wallet Security Breach The Crypto Basic · Sam Wisdom Raphael
- Crypto Wallet Ledger Loses $484K in Fresh Hack, Users May Still Be at Risk Coinspeaker · Mayowa Adebajo
- Supply Chain Attack on Ledger Connect Kit: Analyzing the Impact and Preventive Measures SlowMist
- Crypto Wallet Firm Ledger Reports Security Breach PYMNTS.com
- Understanding the Ledger library exploit and what it means for users CryptoSlate · Oluwapelumi Adejumo
- Blockchain Firm Ledger Confirms Library ConnectKit Compromise Cryptonews · Jimmy Aki
- Ledger resolves security flaw affecting dApps, $500k in user losses Crypto Briefing · Vince Dioquino
- Tether freezes Ledger exploiter's address CryptoSlate · Assad Jafri
- Hacker Hits One of Crypto Industry's Biggest Names in Security Bloomberg · Hannah Miller
- Ledger CEO explains hack, calls it ‘isolated incident’ Cointelegraph · Derek Andersen
- Ledger ex-staff phished in library compromise crypto.news · Naga Avan-Nomayo
- Ledger Hardware Wallet Announces Critical Security Vulnerability, Urges Users To Pause Interacting With DApps The Daily Hodl · Mehron Rokhy
- Ledger dApp supply chain attack steals $600K from crypto wallets BleepingComputer · Bill Toulas
- ‘Decentralized’ apps suffer after Ledger Connect Kit attack Protos · Bennett Tomlin
- Tether freezes wallet of Ledger library exploiter; Ledger provides more details The Block · Anna Baydakova
- Ledger Releases New Connect Kit Version to Mitigate Hack Impact CoinGape · Godfrey Benjamin
- Ledger security breach compromises crypto assets worth $484,000 Cryptopolitan · Damilola Lawrence
- Ledger attacker drained at least $484K Cointelegraph · Ana Paula Pereira
- Just In: Tether Freezes Attacker's Wallet in Ledger Library Exploit CoinGape · Kelvin Munene Murithi
- Ledger Connect Kit Security Breach Spotted and Resolved to Save User Funds Bitcoin Insider · Emma Clarke
- Supply chain attack on Ledger puts much of defi at risk Web3 is Going Just Great
Discussion
-
@ledger
@ledger
on x
FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about...
-
@ledger
@ledger
on x
🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨 A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves. Your Ledger device and...
-
@ledger
@ledger
on x
UPDATE: The genuine Ledger Connect Kit 1.1.8 is now fully propagated. Ledger and WalletConnect can confirm that the malicious code was deactivated. You are now safe to use your Ledger Connect Kit. Reminder that that we always encourage clear signing.
-
@coindesk
@coindesk
on x
At least $484k has been stolen following an exploit to Ledger's popular Connect Kit software library. The hack comes after a Ledger employee was “phished,” and blockchain security experts say DeFi users “remain at risk.” Reporting by @oknightcrypto https://www.coindesk.com/...
-
@__bigjo
@__bigjo
on x
Not up to 24hrs after I made a post on the fact that your assets can never be 100% safe as long as you're using any Non-custodial wallet. Ledger was compromised because of an ex-employee and a malicious link was placed into Ledger's connect kit leading to multiple phishing... [im…