Ledger says attacker conducted phishing attack on former employee

The Ledger attacker was able to upload the malicious code to ConnectKit after phishing a former Ledger employee

article-image

Quinten Jacobs/Shutterstock modified by Blockworks

share

Today’s attack on crypto hardware firm Ledger was traced to an ex-employee who “fell victim to a phishing attack that gained access to their NPMJS account” in an email to Blockworks.

The code was then published to ConnectKit. A fix, according to Ledger, was deployed roughly 40 minutes after they were alerted but not before the malicious code was active for five hours.

The address was connected to a malicious code found in Ledger’s ConnectKit software libraries early Thursday. ConnectKit connects blockchain apps with Ledger devices. 

Loading Tweet..

WalletConnect was able to disable the “rogue project.” Chainalysis posted the address and Tether CEO Paolo Ardoino said his team froze the Ledger exploiter address. 

Loading Tweet..

Ledger told Blockworks that it is working with customers impacted by the attack as well as law enforcement to track the attacker. 

The attack led to SushiSwap and Revoke.cash taking their front-end web apps offline. As Blockworks previously reported, Revoke.cash was impacted by the attack. SushiSwap warned users to avoid interacting with the Sushi page.

Ledger, following the warnings across social media, previously updated that it was able to replace the malicious file with the genuine one.

Loading Tweet..

“In the meantime, we’d like to remind the community to always Clear Sign your transactions — remember that the addresses and the information presented on your Ledger screen is the only genuine information,” Ledger continued. 

The hardware firm added that users should stop the transaction “immediately” if there’s a difference between the Ledger device screen and the screen on a computer or phone.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Screen Shot 2024-05-16 at 14.53.45.png

Research

Loss-versus-rebalancing (LVR) is arguably Ethereum DeFi’s biggest problem, and thus reducing LVR is fundamental to the success of Ethereum. This report dives into the world of LVR. We uncover its importance for AMM designers, discuss the two major mechanism design categories and various projects developing solutions, and offer a higher level perspective on the importance of AMMs in general.

article-image

We need this repeal for the future of our digital economy, the safe custody of cryptocurrencies and the good of the American investor

article-image

The Senate will vote on the anti-SAB 121 resolution tomorrow, and it looks like there are enough Democrats on board to get the legislation to the president’s desk, according to people familiar with the matter

article-image

How Helium Mobile’s plan to decentralize cell coverage is catching on

article-image

The two brothers were arrested in New York and Boston, and they face two courts later Wednesday

article-image

The fund giant will ultimately offer a bitcoin ETF, Digital Assets Council of Financial Professionals founder says

article-image

Just a few months after it confidentially filed for a US IPO, the company is planning to jump across the pond