‘Wallet drainer’ code added to Ledger library has crypto on edge

A suspected “supply chain attack” on Ledger ConnectKit may leave dapp users open to loss of funds

article-image

Ledger Head of Sales Americas Joel Edgerton | DAS 2022 New York by Blockworks

share

Users of crypto web apps are being warned to avoid the platforms until investigations into a potential cybersecurity incident affecting hardware wallet Ledger play out.

Notices of malicious code were shared on social media Thursday morning, found in software libraries for Ledger’s ConnectKit, which connects blockchain apps with Ledger devices.

Web3-focused cybersecurity firm BlockAid told Blockworks that so far at least $150,000 has been lost as a result of the malicious code slipping into websites in production.

Ledger users are not at risk if they refrain from transacting, the firm said.

“It is not exploitable on prior approvals,” CEO Ido Ben-Natan told Blockworks, noting that “many websites are still affected and users are getting hit,” so the damage may be more severe.

Decentralized exchange SushiSwap took its front-end web app offline soon after the warnings.

“We’ve identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps,” SushiSwap posted

“If you have the Sushi page open and see an unexpected ‘Connect Wallet’ pop-up, DO NOT interact or connect your wallet. We’re actively working to remove the ledger wallet connector. For your safety, please refrain from engaging with any dApps until further notice. Stay tuned for updates.”

Revoke.cash, a service which allows crypto users to take back transaction signing powers previously given to Web3 apps, also took its front-end offline to avoid users being duped.

“Revoke.cash specifically is affected, so don’t interact with it,” Ben-Natan said.

Loading Tweet..

Ledger’s official X account initially confirmed the potential attack vector and said the company had removed the malicious code.

The malicious version of the file was replaced with the genuine version at approximately 8:35 am ET. The new version is “propagating,” and will become active soon — effectively ending the threat — depending on the caching of the third party dApps, Philip Costigan, head of public relations at Ledger, told Blockworks.

Funds cannot be outright stolen from Ledger devices if no further actions are taken, and the malicious code was inserted into the software library only very recently — about 6:00 am ET, BlockAid confirmed —  meaning only a small subset of active crypto users could potentially be vulnerable.

Still, out of an abundance of caution, it’s best to avoid crypto web apps altogether, other experts said.

WalletConnect, a popular interface for dapp developers who do not integrate Ledger directly, also put out a warning.

Loading Tweet..

“Do not interact with any dApps for the moment,” Costigan said. “We will keep users informed as the situation evolves. Ledger devices and Ledger Live were not compromised.”

Hackers have similarly targeted front-ends of popular crypto apps before. Nearly 865 ETH ($3 million then, $2 million now) was stolen from SushiSwap users in 2021 in a supply-chain attack on the platform’s token sale platform.

The hack saw the auction wallet for a coin offering replaced with one controlled by the attacker. Other incidents have involved DNS attacks to reroute unsuspecting users to fake versions of platform websites, which upon interaction send funds to the attackers rather than their intended recipients.

Updated Dec. 14, 2023 at 8:34, 8:53, 9:03 and 9:15 am ET with context and comments from Ledger and BlockAid.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Flashnote Template Presentation (2).jpg

Research

With the recent election, it’s clear that there will be a meaningful shift in crypto regulations and legislation. Trump is likely as pro-crypto as a president can be. He launched (multiple) of his own NFT collections and is launching an Aave wrapper called World Liberty Fi. He has also spoken out and mentioned that he wants to make the United States "the crypto capital of the planet" and transform it into the "Bitcoin superpower of the world". He proposed creating a strategic national Bitcoin stockpile alongside support from Senator Cynthia Lummis, promising to retain 100% of all Bitcoin held by the U.S. government. More importantly, we’re likely to see deregulation across the board in a lot of industries, with crypto being one of them - as Trump has committed to keeping the crypto market largely unregulated. Crypto, DeFi in particular, has historically been knee-capped by overreaching and hostile governmental agencies and regulation by enforcement, as evidenced by the plethora of Wells notices and lawsuits over the past few years. With Donald Trump winning the presidency, Republicans taking control of the Senate, and being on the verge of securing the House, we think it’s likely that crypto realizes positive regulatory clarity. Below, you can find our analysts’ takes:

article-image

Solana is the crowd favorite to potentially flip Ethereum somewhere down the line, and it tends to feel realistic at times

article-image

Of course, a lot has happened since the 600+ survey respondents shared their thoughts between Aug. 15 and Oct. 1

article-image

AI’s future shouldn’t be decided by a handful of tech giants

article-image

A look at software wallet Exodus may show how an SEC shakeup could have a real impact on industry companies

article-image

Co-chairing Trump’s transition team to help fill administration positions is Cantor Fitzgerald CEO Howard Lutnick

article-image

Reflect is a delta-neutral currency protocol that lets tokens accrue yield without touching the banking system