Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
Security issue in Ledger ConnectKit library affects multiple decentralized applications

Security issue in Ledger ConnectKit library affects multiple decentralized applications

The BlockThe Block2023/12/14 13:38
By:The Block

Quick Take A significant security vulnerability has been reported by several decentralized applications. The issue stems from a compromised software library connected to Ledger.

Security issue in Ledger ConnectKit library affects multiple decentralized applications image 0

A critical web3 security vulnerability emerged today, reportedly affecting several decentralized applications. The issue is related to a software library from the crypto hardware wallet provider Ledger, the “LedgerHQ” library, that dapps rely on for use with the crypto wallet service. This vulnerability could potentially allow malicious code to be injected into numerous dapps on their front-ends — posing a significant risk to users and their assets.

Consequently, front ends to dapps such as SushiSwap, Kyber, RevokeCash and Zapper could be vulnerable if used. Both Kyber and RevokeCash confirmed on X that they disabled their front-ends. 

According to reports, the library code was replaced with malicious software created by hackers and designed to drain assets. 

Security firm Blockaid described it as a "supply chain attack" on Ledger Connect Kit and claimed that $150,000 had been lost in the past couple of hours. 

The issue likely emerged due to a specific Content Delivery Network used to host the software library being affected, according to Sushi’s chief technology officer Mathew Lilly. “LedgerHQ/connect-kit loads JavaScript from a CDN. Their CDN account has been compromised, which is injecting malicious JavaScript into multiple dApps,” Lilly said.

A potentially software patch was finalized in an update and may need to be adopted by dapps before conditions are safe.

Meanwhile, Lilly and others have warned users to avoid interacting with any dapps until further notice.

Ledger did not immediately respond to a request for comment.


0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

XP raises $6,2 million with Solana and NFTs

Portalcripto2025/05/16 13:22

Heritage Distilling Adopts Crypto Payments

Heritage Distilling Company, Inc. (NASDAQ: CASK) is making a bold foray into the digital economy, becoming one of the first craft spirits producers to implement a formal Cryptocurrency Treasury Reserve Policy. Announced on May 15, the new strategy enables the Washington-based distiller to accept Bitcoin and Dogecoin as payment via its direct-to-consumer (DTC) e-commerce platform while holding these digital assets as part of its broader treasury management plan.

DeFi Planet2025/05/16 12:44
Heritage Distilling Adopts Crypto Payments

Stablecoins Enter Production Era as Institutions Prioritize Growth Over Cost

Stablecoins are quickly moving from pilot projects to a core part of global payment systems, according to Fireblocks’ newly released “State of Stablecoins 2025” report. The digital asset platform revealed that stablecoin transactions on its network now reach $40 billion per quarter, reflecting surging institutional use and a clear shift from experimentation to full-scale implementation.

DeFi Planet2025/05/16 12:44
Stablecoins Enter Production Era as Institutions Prioritize Growth Over Cost

xAI Blames Unauthorized Prompt Change for Grok’s Inflammatory Responses on South Africa

Elon Musk’s artificial intelligence startup, xAI, has disclosed that a controversial series of responses generated by its chatbot, Grok, were the result of an unauthorized internal modification.

DeFi Planet2025/05/16 12:44
xAI Blames Unauthorized Prompt Change for Grok’s Inflammatory Responses on South Africa