Ledger's Crypto & NFT Hardware Wallet Got Hacked

On December 14, Ledger, the company that makes physical crypto wallets, saw its Ledger Connect Kit software compromised, leading to hundreds of dollars being drained from users' wallets.
Blockaid, a renowned crypto security startup, was the first security firm to detect a malicious exploit on Ledger Connect. It wrote, "we've detected a potential supply chain attack on Ledger Connect Kit. The attacker has injected a wallet-draining payload into the popular NPM package. This heist currently affects a couple of popular dapps."
In a short statement, Ledger has plainly explained that the exploit originated from a phishing attack that targeted a former employee. The hacker published malicious code that rerouted user funds to their wallet during transactions with decentralized applications, or dapps, that used the affected software.
The Ledger Company said the malicious code was live for around five hours. Fortunately, its security experts were able to deactivate the malicious code and replace the Ledger Connect Kit in the subject with a new and more secure Ledger Connect Kit.
Based on Blockaid estimate, anywhere from 500 to 1000 crypto wallets were compromised, leading to more than $500,000 being stolen from crypto and NFT users. While commenting about the hack in a short interview, Raz Niv, co-founder and chief technology officer of Blockaid, said that the hack was not specific to Ledger customers and that users of various hardware and software wallets from other providers were also impacted.
In a subsequent blog post, Pascal Gauthier, the chairman and the chief executive officer of Ledger, has remorsefully sympathized with all affected users, vowing to do what it takes to "find this bad actor, bring them to justice." The top executive said the hack of Ledger's Javascript connector library was an "isolated incident" and promised more robust security control.
(Source: inside bitcoins)
Subscribe Now

