Earlier today, crypto hardware wallet manufacturer Ledger confirmed that its Connector library was compromised after attackers replaced a genuine version with a malicious file. Following the incident, several decentralized applications (dApps) faced potential exploits, with the attacker managing to siphon more than $500,000 from multiple wallets.
In this report, CryptoSlate brings you a breakdown of the incident, its key events, and the implications.
What happened?
In an extensive post on social media platform X (formerly Twitter), Ledger explained that a former employee was phished, giving the hackers access to this former employee’s NPMJS account, a software registry owned by GitHub.
Subsequently, the hackers released altered versions of the Ledger Connect Kit, which contained malicious code. This code was employed in a deceptive WalletConnect that redirects funds to a wallet controlled by the hacker.
The malicious versions deceive users by displaying fake prompts upon connection t
We współpracy z: https://cryptoslate.com/understanding-the-ledger-library-exploit/