Ledger quickly resolves a vulnerability that affected multiple DApps, including SushiSwap and Revoke.cash, strengthening security on its platform.
The security breach in Ledger’s connector library underscores the importance of constant vigilance in the crypto ecosystem.
On the morning of December 14, a former Ledger employee suffered a phishing attack that allowed a hacker to access his NPMJS account. The hacker posted a malicious version of the Ledger Connect Kit, affecting versions 1.1.5, 1.1.6 and 1.1.7.
The malicious code used a fraudulent WalletConnect project to redirect funds to the attacker’s wallet. Ledger, realizing the problem, reacted quickly and managed to deploy a patch in just 40 minutes. However, the malicious file was active for approximately 5 hours, with a misappropriation of funds period of at least two hours.
This library vulnerability affected several decentralized applications (DApps), including SushiSwap and Revoke.cash.
The Scope of the Vulnerability
The s
Vitalik Buterin Urges Robust Wallets to Prevent Crypto Losses
[[{„value”:” Ethereum (ETH) co-founder Vitalik Buterin has called for improved wallet security to prevent crypto losses from non-theft…