Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
Ledger says attacker conducted phishing attack on former employee

Ledger says attacker conducted phishing attack on former employee

BlockworksBlockworks2023/12/14 19:07
By:Blockworks

The Ledger attacker was able to upload the malicious code to ConnectKit after phishing a former Ledger employee

Today’s attack on crypto hardware firm Ledger was traced to an ex-employee who “fell victim to a phishing attack that gained access to their NPMJS account” in an email to Blockworks.

The code was then published to ConnectKit. A fix, according to Ledger, was deployed roughly 40 minutes after they were alerted but not before the malicious code was active for five hours.

The address was connected to a malicious code found in Ledger’s ConnectKit software libraries early Thursday. ConnectKit connects blockchain apps with Ledger devices. 

Loading Tweet..

WalletConnect was able to disable the “rogue project.” Chainalysis posted the address and Tether CEO Paolo Ardoino said his team froze the Ledger exploiter address. 

Loading Tweet..

Ledger told Blockworks that it is working with customers impacted by the attack as well as law enforcement to track the attacker. 

The attack led to SushiSwap and Revoke.cash taking their front-end web apps offline. As Blockworks previously reported, Revoke.cash was impacted by the attack. SushiSwap warned users to avoid interacting with the Sushi page.

Ledger, following the warnings across social media, previously updated that it was able to replace the malicious file with the genuine one.

Loading Tweet..

“In the meantime, we’d like to remind the community to always Clear Sign your transactions — remember that the addresses and the information presented on your Ledger screen is the only genuine information,” Ledger continued. 

The hardware firm added that users should stop the transaction “immediately” if there’s a difference between the Ledger device screen and the screen on a computer or phone.

Don’t miss the next big story – join our  free daily newsletter .

Tags
  • Ledger
  • Phishing
  • scam
  • sushiswap
  • Tether
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

XP raises $6,2 million with Solana and NFTs

Portalcripto2025/05/16 13:22

Heritage Distilling Adopts Crypto Payments

Heritage Distilling Company, Inc. (NASDAQ: CASK) is making a bold foray into the digital economy, becoming one of the first craft spirits producers to implement a formal Cryptocurrency Treasury Reserve Policy. Announced on May 15, the new strategy enables the Washington-based distiller to accept Bitcoin and Dogecoin as payment via its direct-to-consumer (DTC) e-commerce platform while holding these digital assets as part of its broader treasury management plan.

DeFi Planet2025/05/16 12:44
Heritage Distilling Adopts Crypto Payments

Stablecoins Enter Production Era as Institutions Prioritize Growth Over Cost

Stablecoins are quickly moving from pilot projects to a core part of global payment systems, according to Fireblocks’ newly released “State of Stablecoins 2025” report. The digital asset platform revealed that stablecoin transactions on its network now reach $40 billion per quarter, reflecting surging institutional use and a clear shift from experimentation to full-scale implementation.

DeFi Planet2025/05/16 12:44
Stablecoins Enter Production Era as Institutions Prioritize Growth Over Cost

xAI Blames Unauthorized Prompt Change for Grok’s Inflammatory Responses on South Africa

Elon Musk’s artificial intelligence startup, xAI, has disclosed that a controversial series of responses generated by its chatbot, Grok, were the result of an unauthorized internal modification.

DeFi Planet2025/05/16 12:44
xAI Blames Unauthorized Prompt Change for Grok’s Inflammatory Responses on South Africa