News

Ledger Connect Kit Exploit Still Under Active Investigation

Key Points:
  • Ledger faced a brief security breach on December 14th through its Connect Kit, affecting third-party DApps.
  • The wallet issuer swiftly addressed the Ledger Connect Kit exploit, freezing stolen funds, filing a complaint, and deactivating malicious code within two hours.
  • It plans to enhance security measures, connecting its build pipeline to NPM for continuous improvement in cybersecurity.
In a public letter, Pascal Gauthier, Chairman and CEO of Ledger, addressed a recent security breach involving the Ledger Connect Kit exploit, a Javascript library linking websites to wallets.

Ledger’s Swift Response to Ledger Connect Kit Exploit

On December 14, hackers exploited the kit, prompting Ledger to swiftly eliminate the vulnerability with its partners. The breach was limited to third-party dApps using the Ledger Connect Kit and is currently under investigation.

Ledger, known for stringent security practices, emphasized that the incident was an isolated case. The company, which filed a complaint, has frozen stolen funds and pledged assistance to affected users in recovering their assets. Ledger is actively cooperating with law enforcement to track and apprehend the perpetrators.

Ledger Takes Proactive Measures After Recent Security Incident

To enhance security measures, Ledger plans to implement stricter controls in its build pipeline, connecting it to the NPM distribution channel. The company emphasized the dynamic nature of security and the need for continuous improvement.

The letter revealed that the Ledger Connect Kit exploit resulted from a former employee falling victim to a phishing attack, allowing the malicious code to run for less than two hours. Ledger promptly released Connect Kit version 1.1.8, deactivating the malicious code in Ledger and WalletConnect. While users are now safe, Ledger recommends waiting 24 hours and clearing the browser cache as a precautionary measure.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

Best Cryptos with 1000X Potential: Qubetics Revolutionises Blockchain as Polkadot and Cosmos Shape the Future

Discover why Qubetics, Polkadot, and Cosmos are the best cryptos with 1000X potential, offering innovation,…

2 hours ago

Best Coins to Buy in December 2024: Qubetics Offer 630% ROI, Polkadot Delivers on Interoperability and Near Protocol’s Scalability is Talk of the Town

Explore the best coins to buy in December 2024—Qubetics with its thrilling presale, Polkadot’s interoperability,…

8 hours ago

Crypto Market Outlook 2025 Key Factors to Watch

The Crypto Market Outlook 2025 highlights key areas: stablecoin growth, tokenization, crypto ETFs, DeFi innovation,…

11 hours ago

Bitcoin Quantum Computing Threat Expected to Take Decades

The Bitcoin quantum computing threat is years away, but reserves already support post-quantum signatures via…

11 hours ago

Best New Meme Coins to Invest in Today: BTFD Coin Wows Investors with Unmissable Stage-7 Price Reversal as Book of Meme and Snek Crash

Don't miss BTFD Coin's Stage-7 presale dip! Find out why it's leading the pack of…

11 hours ago

Crypto Hedge Funds Banking Issues Persist Over Recent Years

A WSJ survey reveals crypto hedge funds banking issues over three years, with 120 out…

11 hours ago

This website uses cookies.