Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
‘Wallet drainer’ code added to Ledger library has crypto on edge

‘Wallet drainer’ code added to Ledger library has crypto on edge

BlockworksBlockworks2023/12/14 19:07
By:Blockworks

A suspected “supply chain attack” on Ledger ConnectKit may leave dapp users open to loss of funds

Users of crypto web apps are being warned to avoid the platforms until investigations into a potential cybersecurity incident affecting hardware wallet Ledger play out.

Notices of malicious code were shared on social media Thursday morning, found in software libraries for Ledger’s ConnectKit, which connects blockchain apps with Ledger devices.

Web3-focused cybersecurity firm BlockAid told Blockworks that so far at least $150,000 has been lost as a result of the malicious code slipping into websites in production.

Ledger users are not at risk if they refrain from transacting, the firm said.

“It is not exploitable on prior approvals,” CEO Ido Ben-Natan told Blockworks, noting that “many websites are still affected and users are getting hit,” so the damage may be more severe.

Decentralized exchange SushiSwap took its front-end web app offline soon after the warnings.

“We’ve identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps,” SushiSwap posted . 

“If you have the Sushi page open and see an unexpected ‘Connect Wallet’ pop-up, DO NOT interact or connect your wallet. We’re actively working to remove the ledger wallet connector. For your safety, please refrain from engaging with any dApps until further notice. Stay tuned for updates.”

Revoke.cash, a service which allows crypto users to take back transaction signing powers previously given to Web3 apps, also took its front-end offline to avoid users being duped.

“Revoke.cash specifically is affected, so don’t interact with it,” Ben-Natan said.

Loading Tweet..

Ledger’s official X account initially confirmed the potential attack vector and said the company had removed the malicious code.

The malicious version of the file was replaced with the genuine version at approximately 8:35 am ET. The new version is “propagating,” and will become active soon — effectively ending the threat — depending on the caching of the third party dApps, Philip Costigan, head of public relations at Ledger, told Blockworks.

Funds cannot be outright stolen from Ledger devices if no further actions are taken, and the malicious code was inserted into the software library only very recently — about 6:00 am ET, BlockAid confirmed —  meaning only a small subset of active crypto users could potentially be vulnerable.

Still, out of an abundance of caution, it’s best to avoid crypto web apps altogether, other experts said.

WalletConnect, a popular interface for dapp developers who do not integrate Ledger directly, also put out a warning.

Loading Tweet..

“Do not interact with any dApps for the moment,” Costigan said. “We will keep users informed as the situation evolves. Ledger devices and Ledger Live were not compromised.”

Hackers have similarly targeted front-ends of popular crypto apps before. Nearly 865 ETH ($3 million then, $2 million now) was stolen from SushiSwap users in 2021 in a supply-chain attack on the platform’s token sale platform.

The hack saw the auction wallet for a coin offering replaced with one controlled by the attacker. Other incidents have involved DNS attacks to reroute unsuspecting users to fake versions of platform websites, which upon interaction send funds to the attackers rather than their intended recipients.

Updated Dec. 14, 2023 at 8:34, 8:53, 9:03 and 9:15 am ET with context and comments from Ledger and BlockAid.

Don’t miss the next big story – join our  free daily newsletter .

Tags
  • dApps
  • exploit
  • Ledger
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Subscribe to TANSSI Savings and enjoy up to 15% APR

Bitget Announcement2025/07/15 11:00

TACUSDT now launched for futures trading and trading bots

Bitget Announcement2025/07/15 10:40

Bitget Spot Bot adds PUMP/USDT

Bitget Announcement2025/07/15 08:00