Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Tether Freezes Ledger Exploiter Loot in Wild 24 Hours for DeFi

Tether Freezes Ledger Exploiter Loot in Wild 24 Hours for DeFi

DailyCoinDailyCoin2023/12/15 18:07
By:DailyCoin
  • Tether has frozen USDT belonging to the Ledger exploiter.
  • The exploiter made off with an estimated $600k in crypto assets.
  • The hack has been linked to a former Ledger employee.

Over the past 24 hours, a hacker spread panic across the entire DeFi ecosystem by hacking Ledger’s Connect Kit library to mount a large-scale wallet-draining exploit across multiple decentralized applications. However, this hacker’s reign of terror proved fleeting, as Ledger quickly responded with a fix. In addition to this, part of the hacker’s loot has now been frozen by Tether as investigations enter high gear.

Ledger Exploiter Loot Frozen

In an X post hours after the Ledger exploit on Thursday, December 14, Tether CEO Paolo Ardoino revealed that the firm had frozen the USDT of the hacker.

Tether just froze the Ledger exploiter address

— Paolo Ardoino 🍐 (@paoloardoino) December 14, 2023

The development comes as investigations into the attack and efforts to recover the estimated $600k in losses enter high gear. 

Per analysis of Arkham Intelligence data at the time of writing, the drainer address shared by Ledger now holds only about $274k, as the hacker has made efforts to spread the loot over the past 24 hours. The current balance includes 44k USDT, which Tether has now frozen. 

The Ledger Hack Unraveled

In a final update to customers and crypto community members at about 3:49 pm UTC on Thursday, December 14, Ledger explained that the hacker had gained access to Ledger’s internal systems by duping a former employee via a phishing attack.

FINAL TIMELINE AND UPDATE TO CUSTOMERS:

4:49pm CET:

Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.

The investigation continues, here is the timeline of what we know about…

— Ledger (@Ledger) December 14, 2023

After gaining access to Ledger’s systems, the hacker infused malicious software into the firm’s Connect Kit, which was integrated with multiple DApps to allow users to facilitate transactions from their Ledger hardware wallet. With this malware in place, the hacker was able to compromise the front end of several DApps, including SushiSwap, Zapper, and Revoke.Cash prompts unsuspecting users to connect their wallet to a drainer.

Ledger noted that the malware was up for approximately five hours, with most of the hacker’s loot obtained within the first two, likely due to prompt warnings from several influential crypto community members, including Sushi CTO Matthew Lilley.

While Ledger quickly released a fix, the firm cautioned users to wait 24 hours before using DApps that use the Connect Kit as developers may take different timelines to implement necessary changes.

The hardware wallet service provider has contacted Chainalysis for help hunting down the perpetrator and recovering user funds.

On the Flipside

  • The freezing of the Ledger exploiter’s USDT sparked renewed Tether centralization concerns within the crypto community.
  • The amount frozen by Tether represents a small fraction of the exploiter’s total loot.
  • Despite Ledger’s assurances, several crypto community members remain skeptical about using dApps that support the Connect Kit.

Why This Matters 

Tether’s action highlights that progress is being made to recoup user funds, bringing hope to victims of the recent exploit.

Read this to learn more about the Ledger hack:
Sushi CTO Warns Ledger Connector Exploited: How to Stay Safe

Find out how Polygon benefits from CCTP support:
Here’s How Polygon Benefits from Circle (USDC) CCTP Support

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

ESUSDT now launched for futures trading and trading bots

Bitget Announcement2025/07/16 11:12

New spot margin trading pair — CROSS/USDT, TAC/USDT!

Bitget Announcement2025/07/16 08:07

Subscribe to TANSSI Savings and enjoy up to 15% APR

Bitget Announcement2025/07/15 11:00

TACUSDT now launched for futures trading and trading bots

Bitget Announcement2025/07/15 10:40