Ledger has since attributed the exploit to a phishing attack on a former employee.
News
More decentralized applications (dApps) have temporarily disabled their front-end user interface for Ledger Connect amid today’s exploit.
Developers of nonfungible tokens (NFT) platform OpenSea said on December 14 that users should “not connect to any dApps using Ledger Connect until further notice.”
Meanwhile, decentralized finance (DeFi) protocol Lido Finance stated its “front-ends have been switched off as a precautionary measure whilst the Ledger connect issue is being investigated.”
Earlier in the day, the front ends of Zapper, SushiSwap, Phantom, Balancer and Revoke.cash were compromised as part of the Ledger Connect exploit. Ledger has since stated that the exploit had been patched, with the issue stemming from a “malicious version of the Ledger Connect Kit.”
“A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.”
Preliminary reports claim that the attack has drained at least $484,000 in digital assets. Tether, the issuer of the USDT stablecoin, has since frozen the exploiter’s address. According to Ledger developers, a “genuine version” of the Ledger Connect Kit is “being propagated now automatically.” That said, users are recommended to wait 24 hours before using the Kit again.
The exploit has been attributed to a phishing attack on a former Ledger employee, which allowed hackers to gain access to sensitive information. “We are filing a complaint and working with law enforcement on the investigation to find the attacker,” developers wrote. An estimated two hours lapsed between the draining of funds and when a fix was deployed.
FINAL TIMELINE AND UPDATE TO CUSTOMERS:
4:49pm CET:
Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.
The investigation continues, here is the timeline of what we know about…
— Ledger (@Ledger) December 14, 2023
Related: Fake Ledger Live app sneaks into Microsoft’s app store, $588K stolen
This article first appeared at Cointelegraph.com News