Ledger says attacker conducted phishing attack on former employee

The Ledger attacker was able to upload the malicious code to ConnectKit after phishing a former Ledger employee


Quinten Jacobs/Shutterstock modified by Blockworks


Today’s attack on crypto hardware firm Ledger was traced to an ex-employee who “fell victim to a phishing attack that gained access to their NPMJS account” in an email to Blockworks.

The code was then published to ConnectKit. A fix, according to Ledger, was deployed roughly 40 minutes after they were alerted but not before the malicious code was active for five hours.

The address was connected to a malicious code found in Ledger’s ConnectKit software libraries early Thursday. ConnectKit connects blockchain apps with Ledger devices. 

Loading Tweet..

WalletConnect was able to disable the “rogue project.” Chainalysis posted the address and Tether CEO Paolo Ardoino said his team froze the Ledger exploiter address. 

Loading Tweet..

Ledger told Blockworks that it is working with customers impacted by the attack as well as law enforcement to track the attacker. 

The attack led to SushiSwap and Revoke.cash taking their front-end web apps offline. As Blockworks previously reported, Revoke.cash was impacted by the attack. SushiSwap warned users to avoid interacting with the Sushi page.

Ledger, following the warnings across social media, previously updated that it was able to replace the malicious file with the genuine one.

Loading Tweet..

“In the meantime, we’d like to remind the community to always Clear Sign your transactions — remember that the addresses and the information presented on your Ledger screen is the only genuine information,” Ledger continued. 

The hardware firm added that users should stop the transaction “immediately” if there’s a difference between the Ledger device screen and the screen on a computer or phone.

Don’t miss the next big story – join our free daily newsletter.


Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

ao cover.jpg


Arweave recently launched the testnet for AO computer, a new messaging protocol that will sit atop a PoS network and aims to become a scalable global compute platform through parallel processing and modularity.


The US spot bitcoin fund category has notched negative net flows over the course of a week just three times since coming to market in January


Elsewhere, rank-and-file employees move around and Binance’s head of legal in Europe departs


Plus, a Dragonfly partner shares his view on the crypto VC market, and a mining hardware firm raises $80 million


Plus, a Bored Ape burger restaurant closes, and Crypto: The Game presses on


Bitcoin scarcity is a meme, with or without the halvings


The current state of blockchain interoperability poses an existential threat to the mainstream adoption of blockchain technology as a whole