Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Ledger patches vulnerability after multiple DApps using connector library were compromised

CryptoExpert by CryptoExpert
December 14, 2023
in Altcoin News
0
Ledger patches vulnerability after multiple DApps using connector library were compromised
  • Facebook
  • Twitter
  • Pinterest



You might also like

Bitcoin Exchange Supply Keeps Falling: What Happens If Demand Returns?

‘Dead Meme’ or Major Opportunity? DOGE Is Flashing The Same Signal That Preceded Its Biggest Rallies

Hyperliquid Bear Flips Bullish After Losing Over $46M Betting on HYPE Price to Drop

Update (Dec. 14 at 2:45 pm UTC): This article has been updated to clarify that Ledger has reportedly fixed the issue.

The front end of multiple decentralized applications (DApps) using Ledger’s connector, including Zapper, SushiSwap, Phantom, Balancer and Revoke.cash were compromised on Dec. 14. Nearly three hours after the security breach was discovered, Ledger reported that the malicious version of the file had been replaced with its genuine version around 1:35 pm UTC.

Ledger is warning users “to always Clear Sign” transactions, adding that the addresses and the information presented on the Ledger screen are the only genuine information. “If there’s a difference between the screen shown on your Ledger device and your computer/phone screen, stop that transaction immediately.”

SushiSwap chief technical officer Matthew Lilley was among the first to report the issue, noting that a commonly used Web3 connector was compromised, allowing malicious code to be injected into numerous DApps. The on-chain analyst said the Ledger library confirmed the compromise where the vulnerable code inserted the drainer account address.

okex

RED ALERT :

Do not interact with ANY dApps until further notice. It appears that a commonly used web3 connector has been compromised which allows for injection of malicious code affecting numerous dApps.

— I’m Software (@MatthewLilley) December 14, 2023

Lilley blamed Ledger for the ongoing vulnerability and compromise on multiple DApps. The exec claimed that Ledger’s content delivery network was compromised, with JavaScript being loaded from the compromised network.

seems like the Ledger’s @ledgerhq/connect-kit npm package was hacked, the latest publish was 2 hours ago. https://t.co/jFb6CThljS pic.twitter.com/AsbA675D9Q

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) December 14, 2023

Ledger connector is a library used by many DApps and maintained by Ledger. A wallet drainer has been added, so draining assets from a user’s account might not happen on its own. However, prompts from a browser wallet like MetaMask will display and could give malicious actors access to the assets.

Lilley warned users to avoid any DApps using the Ledger connector, adding that the “connect-kit” is also vulnerable, and that this isn’t a single isolated attack but a large-scale attack on multiple DApps.

The vulnerability with Ledger Connect Kit should be resolved now

This appears to have been an EVM-only exploit, but we can confirm Phantom users on dapps with compromised front-ends would have seen the proper warnings in our transaction preview.

— Phantom (@phantom) December 14, 2023

Polygon Labs vice president Hudson Jameson said even after Ledger corrects the bad code in its library, projects using and deploying the library will need to update before it is safe to use DApps using Ledger’s Web3 libraries.

looks like $610K+ drained

drainer customer0x658729879fca881d9526480b82ae00efc54b5c2ddrainer fee address 0x412f10AAd96fD78da6736387e2C84931Ac20313f pic.twitter.com/Rld2BsKNDo

— ZachXBT (@zachxbt) December 14, 2023

Ido Ben-Natan, co-founder and CEO of Blockaid, told Cointelegraph:

“Ledger users are not at risk if not transacting. It is not exploitable on prior approvals. Revoke.cash specifically is affected, so don’t interact with it. the number of impacted funds is hundreds of thousands of dollars over the past two hours. Many websites are still affected, and users are getting hit.”

Related: KyberSwap hacker demands complete control over Kyber company

Ledger acknowledged the vulnerability in its code and said it has “removed a malicious version of the Ledger Connect Kit,” adding that “a genuine version is being pushed to replace the malicious file now.“

We have identified and removed a malicious version of the Ledger Connect Kit.

A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.

Your Ledger device and…

— Ledger (@Ledger) December 14, 2023

Magazine: HTX hacked again for $30M, 100K Koreans test CBDC, Binance 2.0: Asia Express





Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

Bitcoin Exchange Supply Keeps Falling: What Happens If Demand Returns?

by CryptoExpert
June 4, 2026
0
Bitcoin Exchange Supply Keeps Falling: What Happens If Demand Returns?

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin is trading above $65,000 after a 12% breakdown over two days that erased weeks...

Read more

‘Dead Meme’ or Major Opportunity? DOGE Is Flashing The Same Signal That Preceded Its Biggest Rallies

by CryptoExpert
June 4, 2026
0
Dogecoin (DOGE) Could Surge by Another 30% if its Price Holds This Level: Analyst

The market sees DOGE as a "dead meme," but Alphractal said the chart is signaling a "coiled spring" instead. Dogecoin (DOGE) suffered a fresh decline of over...

Read more

Hyperliquid Bear Flips Bullish After Losing Over $46M Betting on HYPE Price to Drop

by CryptoExpert
June 3, 2026
0
Cointelegraph

A crypto whale who stubbornly held his HYPE short through May’s rally has finally been punished as Hyperliquid’s token kept climbing.Key takeaways:Trader has opened fresh long positions in...

Read more

Bitcoin Whales Most Active In 6 Weeks As BTC Drops To $67K

by CryptoExpert
June 3, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure On-chain data shows the latest crash in the Bitcoin price has come alongside a spike...

Read more

Dogecoin (DOGE) Dips Below $0.10, Yet Key Indicator Flashes a Buy Signal

by CryptoExpert
June 3, 2026
0
Dogecoin (DOGE) Dips Below $0.10, Yet Key Indicator Flashes a Buy Signal

"This old meme coin is about to do something insane," one X user predicted. The largest meme coin by market capitalization has followed the broader crypto market’s...

Read more
Next Post
Did you miss Pepe and Bonk? Memeinator (MMTR) could be next

Did you miss Pepe and Bonk? Memeinator (MMTR) could be next

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 63,679.00
ethereum
Ethereum (ETH) $ 1,777.60
tether
Tether (USDT) $ 0.998949
bnb
BNB (BNB) $ 602.86
usd-coin
USDC (USDC) $ 0.999735
xrp
XRP (XRP) $ 1.17
solana
Solana (SOL) $ 69.95
tron
TRON (TRX) $ 0.328703
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.00
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?