Ledger says attacker conducted phishing attack on former employee

The Ledger attacker was able to upload the malicious code to ConnectKit after phishing a former Ledger employee

article-image

Quinten Jacobs/Shutterstock modified by Blockworks

share

Today’s attack on crypto hardware firm Ledger was traced to an ex-employee who “fell victim to a phishing attack that gained access to their NPMJS account” in an email to Blockworks.

The code was then published to ConnectKit. A fix, according to Ledger, was deployed roughly 40 minutes after they were alerted but not before the malicious code was active for five hours.

The address was connected to a malicious code found in Ledger’s ConnectKit software libraries early Thursday. ConnectKit connects blockchain apps with Ledger devices. 

Loading Tweet..

WalletConnect was able to disable the “rogue project.” Chainalysis posted the address and Tether CEO Paolo Ardoino said his team froze the Ledger exploiter address. 

Loading Tweet..

Ledger told Blockworks that it is working with customers impacted by the attack as well as law enforcement to track the attacker. 

The attack led to SushiSwap and Revoke.cash taking their front-end web apps offline. As Blockworks previously reported, Revoke.cash was impacted by the attack. SushiSwap warned users to avoid interacting with the Sushi page.

Ledger, following the warnings across social media, previously updated that it was able to replace the malicious file with the genuine one.

Loading Tweet..

“In the meantime, we’d like to remind the community to always Clear Sign your transactions — remember that the addresses and the information presented on your Ledger screen is the only genuine information,” Ledger continued. 

The hardware firm added that users should stop the transaction “immediately” if there’s a difference between the Ledger device screen and the screen on a computer or phone.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (19).png

Research

Built on Solana, Loopscale is an orderbook-based lending protocol that pairs the efficiency of direct market matching with the flexibility and UX of modular protocols. We believe Loopscale can help scale NNAs in Solana DeFi and act as their foundational credit layer. Stablecoin deposits and select USD-pegged Loops on Loopscale are offering competitive yields, with an additional upside from farming the protocol and adjacent ecosystem projects (e.g., OnRe, Hylo) for potential future airdrops.

article-image

A recent mistrial illustrates how juries need more background information when it comes to judging complex systems like Ethereum

article-image

The Senate advanced a bipartisan funding package aimed at ending the shutdown, and bitcoin rose from its $100K bottom

article-image

The team is betting that a 20-minute hardware trust window beats a new alt-L1

article-image

To learn how to navigate the physical world, robots need visual data

article-image

Risks and illiquidity come to surface in the wake of a red October

article-image

Advice from Neal Stephenson, Kyle Broflovski, and Crypto Mom on building in crypto