Decentralized applications pause Ledger Connect as exploit fix deployed

Must read

Ledger has since attributed the exploit to a phishing attack on a former employee.

778 Total views

13 Total shares

Decentralized applications pause Ledger Connect as exploit fix deployed

More decentralized applications (DApps) have temporarily disabled their front-end user interface for Ledger Connect amid an exploit on Dec. 14.

Developers of the nonfungible token (NFT) platform OpenSea said on Dec. 14 that users should “not connect to any dApps using Ledger Connect until further notice.”

Meanwhile, the decentralized finance (DeFi) protocol Lido Finance stated its “front-ends have been switched off as a precautionary measure whilst the Ledger connect issue is being investigated.”

Earlier in the day, the front ends of Zapper, SushiSwap, Phantom, Balancer and were compromised as part of the Ledger Connect exploit. Ledger has since stated that the exploit has been patched, with the issue stemming from a “malicious version of the Ledger Connect Kit.”

“A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.”

Preliminary reports claim that the attack has drained at least $484,000 in digital assets. Tether, the issuer of the Tether (USDT) stablecoin, has since frozen the exploiter’s address. According to Ledger developers, a “genuine version” of the Ledger Connect Kit is “being propagated now automatically.” That said, users are recommended to wait 24 hours before using the kit again.

The exploit has been attributed to a phishing attack on a former Ledger employee, allowing hackers to access sensitive information. “We are filing a complaint and working with law enforcement on the investigation to find the attacker,” developers wrote. An estimated two hours lapsed between the draining of funds and when a fix was deployed.


4:49pm CET:

Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.

The investigation continues, here is the timeline of what we know about…

— Ledger (@Ledger) December 14, 2023

Related: Fake Ledger Live app sneaks into Microsoft’s app store, $588K stolen

More articles

Latest article