Ledger Connect Kit supply chain attack
On December 14, 2023, a supply chain attack targeted Ledger’s Connect Kit, a JavaScript library used by many decentralized applications to integrate Ledger hardware wallets.
A malicious version of the library was published to the npm registry, containing code that redirected users to a phishing site designed to steal crypto assets.
Several major dApps, including SushiSwap and Revoke.cash, were affected, prompting immediate action to remove the compromised version and restore secure functionality.
The attack lasted for several hours before Ledger regained control of the library and published a safe update. Users who interacted with affected dApps during the incident may have been exposed to theft.
Ledger confirmed that the breach occurred through a former employee’s compromised account and emphasized the importance of verifying wallet interactions and using trusted sources.
FAQ
What is Ledger Connect Kit?
It’s a JavaScript library that allows dApps to connect with Ledger hardware wallets.
How did the attack happen?
A malicious update was uploaded to the npm registry, redirecting users to a phishing site.
What should affected users do?
Users should revoke suspicious approvals, check wallet activity, and avoid interacting with unverified dApps.