Security issue in Ledger ConnectKit library affects multiple decentralized applications

Quick Take

  • A security issue in Ledger software impacted several decentralized applications.
  • The issue stemmed from a compromised software library connected to the wallet provider.

A critical Web3 security issue emerged today, reportedly affecting several decentralized applications. The issue was related to a software library from the hardware wallet provider Ledger that dapps relied on.

The incident allowed malicious code to be injected into numerous dapps on their front-ends, posing a significant risk to users and their assets. Consequently, front ends to multiple dapps could be vulnerable if used. Projects like Kyber and RevokeCash confirmed on X that they disabled their front-ends.

Security firm Blockaid described it as a “supply chain attack” on Ledger ConnectKit — wherein an attacker replaced the library software with malicious code to drain assets.

The issue may have emerged due to an alleged compromise of a specific content delivery network (CDN) that hosted the said software library, according to Sushi’s chief technology officer Matthew Lilley. “LedgerHQ/connect-kit loads JS [JavaScript] from a CDN, their CDN account has been compromised which is injecting malicious JS into multiple dApps,” Lilley said. He added that any dApp which makes use of LedgerHQ/connect-kit was vulnerable.

Blockaid estimated that $150,000 had been lost in the first couple of hours of the incident. Later the stolen value of funds rose to over half a million dollars. Stablecoin issuer Tether blacklisted the hacker's address.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

Ledger responds

A software patch has been finalized in an update and may need to be adopted by dapps before conditions are safe. “We have identified and removed a malicious version of the Ledger Connect Kit. A genuine version is being pushed to replace the malicious file now,” Ledger said in a statement.

Meanwhile, Lilley and others have warned users to avoid interacting with any dapps until further notice.

MetaMask, the most widely used web3 wallet app said the incident affects all users, not just Ledger. It has deployed a fix for its app and asked users to update to the latest version.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Vishal Chawla is The Block’s crypto ecosystems editor and has spent over six years covering tech protocols, cybersecurity, artificial intelligence and cloud computing. Vishal likes to delve deep into blockchain intricacies to ensure readers are well-informed about the continuously evolving crypto landscape. He is also a staunch advocate for rigorous security practices in the space. Before joining The Block, Vishal held positions at IDG ComputerWorld, CIO, and Crypto Briefing. He can be reached on Twitter at @vishal4c and via email at [email protected]

Editor

To contact the editor of this story:
Adam James at
[email protected]