Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Ledger ConnectKit Library Compromised with a Drainer, Posing Security Risks to Web3 Apps

Altszn.com by Altszn.com
December 14, 2023
in Metaverse, Web3
0
Ledger ConnectKit Library Compromised with a Drainer, Posing Security Risks to Web3 Apps
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter

[ad_1]

by Nik Asti

Published: December 14, 2023 at 8:48 am Updated: December 14, 2023 at 8:48 am

by Victor Dey

Edited and fact-checked:
December 14, 2023 at 8:48 am

To improve your local-language experience, sometimes we employ an auto-translation plugin. Please note auto-translation may not be accurate, so read original article for precise information.

In Brief

The breach of Ledger’s ConnectKit library, which replaced the legitimate tool with a drainer script, exposed numerous Web 3.0 apps.

Ledger ConnectKit Library Compromised, Posing Security Risks to Web 3.0 Applications

A security breach occurred in the Web3 sphere, compromising the Ledger ConnectKit library, crucial for linking Ledger Live with applications. This hack involves the replacement of the library with a ‘drainer’ script, posing a serious threat to user funds.

The compromised package, ConnectKit —- automatically loads a JavaScript script from cdn.jsdelivr.net, which includes a drainer, into the global scope.

This infiltration made the frontend of applications using this library vulnerable, particularly after user authorization. Reports indicate that attackers have altered the wallet connection modal window, putting all wallet owners at risk, not just those using Ledger Live.

🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨

A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.

Your Ledger device and…

— Ledger (@Ledger) December 14, 2023

Warnings Issued by Ledger Security

Notable cryptocurrency security experts, including banteg, have confirmed the Ledger library’s compromise and are advising against interactions with any decentralized applications (dApps) until more clarity emerges. The vulnerability appears to also affect the ledger connect-kit-loader, as it specifies the dependency loosely.

The attack potentially impacts a wide range of parties, as indicated by a list of affected libraries and applications using the @ledgerhq/connect-kit. Ledger’s suggestion to use connect-kit loader for loading connect-kit exacerbates the issue, as even pinned versions of the loader fetch the latest version of connect-kit, leading to widespread infiltration.

🚨 ledger library confirmed compromised and replaced with a drainer. wait out interacting with any dapps till things become clearer.https://t.co/xapunW8zC3 pic.twitter.com/NlAc11vhdv

— banteg (@bantg) December 14, 2023

Attackers have managed to compromise a significant number of libraries by targeting just the connect-kit. Ledger identifies version 1.1.4 as the last known safe release, but considers all releases up to 1.1.7, posted on the day of the attack, as compromised.

This security incident underscores the critical importance of robust cybersecurity measures in the rapidly evolving Web 3.0 domain, where even well-established tools like Ledger’s library are not immune to sophisticated cyber attacks.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Nik is an accomplished analyst and writer at Metaverse Post, specializing in delivering cutting-edge insights into the fast-paced world of technology, with a particular emphasis on AI/ML, XR, VR, on-chain analytics, and blockchain development. His articles engage and inform a diverse audience, helping them stay ahead of the technological curve. Possessing a Master’s degree in Economics and Management, Nik has a solid grasp of the nuances of the business world and its intersection with emergent technologies.

More articles

Nik Asti



Nik is an accomplished analyst and writer at Metaverse Post, specializing in delivering cutting-edge insights into the fast-paced world of technology, with a particular emphasis on AI/ML, XR, VR, on-chain analytics, and blockchain development. His articles engage and inform a diverse audience, helping them stay ahead of the technological curve. Possessing a Master’s degree in Economics and Management, Nik has a solid grasp of the nuances of the business world and its intersection with emergent technologies.



More articles



[ad_2]

Read More: mpost.io

Tags: appsCompromisedConnectKitdrainerLedgerLibraryMetaverseposingRisksSecurityWeb3
ADVERTISEMENT

Recent

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025
U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

June 10, 2025

Categories

  • Bitcoin (4,103)
  • Blockchain (9,902)
  • Crypto (7,825)
  • Dark Web (298)
  • DeFi (7,684)
  • Ethereum (4,086)
  • Metaverse (5,857)
  • Monero (166)
  • NFT (609)
  • Solana (4,760)
  • Web3 (18,554)
  • Zcash (418)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

    VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

    June 15, 2025
    Is it the future of finance?

    Is it the future of finance?

    June 15, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 101,244.00
    • ethereumEthereum (ETH) $ 2,240.50
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.02
    • bnbBNB (BNB) $ 619.60
    • solanaSolana (SOL) $ 132.91
    • usd-coinUSDC (USDC) $ 0.999797
    • tronTRON (TRX) $ 0.265815
    • dogecoinDogecoin (DOGE) $ 0.152534
    • staked-etherLido Staked Ether (STETH) $ 2,239.08
    • cardanoCardano (ADA) $ 0.544959
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 101,263.00
    • hyperliquidHyperliquid (HYPE) $ 35.80
    • wrapped-stethWrapped stETH (WSTETH) $ 2,702.38
    • bitcoin-cashBitcoin Cash (BCH) $ 449.28
    • suiSui (SUI) $ 2.49
    • leo-tokenLEO Token (LEO) $ 9.06
    • chainlinkChainlink (LINK) $ 11.68
    • stellarStellar (XLM) $ 0.229938
    • usdsUSDS (USDS) $ 0.999775
    • avalanche-2Avalanche (AVAX) $ 16.69
    • whitebitWhiteBIT Coin (WBT) $ 48.22
    • the-open-networkToncoin (TON) $ 2.74
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999793
    • shiba-inuShiba Inu (SHIB) $ 0.000011
    • litecoinLitecoin (LTC) $ 80.09
    • wethWETH (WETH) $ 2,241.37
    • wrapped-eethWrapped eETH (WEETH) $ 2,398.88
    • hedera-hashgraphHedera (HBAR) $ 0.135619
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • moneroMonero (XMR) $ 303.20
    • polkadotPolkadot (DOT) $ 3.17
    • bitget-tokenBitget Token (BGB) $ 4.07
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 101,345.00
    • pi-networkPi Network (PI) $ 0.506562
    • uniswapUniswap (UNI) $ 6.28
    • pepePepe (PEPE) $ 0.000009
    • daiDai (DAI) $ 0.999813
    • aaveAave (AAVE) $ 228.89
    • okbOKB (OKB) $ 53.18
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • bittensorBittensor (TAO) $ 306.87
    • aptosAptos (APT) $ 3.94
    • susdssUSDS (SUSDS) $ 1.06
    • crypto-com-chainCronos (CRO) $ 0.080698
    • internet-computerInternet Computer (ICP) $ 4.61
    • jito-staked-solJito Staked SOL (JITOSOL) $ 160.83
    • nearNEAR Protocol (NEAR) $ 1.91
    • ethereum-classicEthereum Classic (ETC) $ 15.20
    • bitcoinBitcoin (BTC) $ 101,244.00
    • ethereumEthereum (ETH) $ 2,240.50
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.02
    • bnbBNB (BNB) $ 619.60
    • solanaSolana (SOL) $ 132.91
    • usd-coinUSDC (USDC) $ 0.999797
    • tronTRON (TRX) $ 0.265815
    • dogecoinDogecoin (DOGE) $ 0.152534
    • staked-etherLido Staked Ether (STETH) $ 2,239.08
    • cardanoCardano (ADA) $ 0.544959
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 101,263.00
    • hyperliquidHyperliquid (HYPE) $ 35.80
    • wrapped-stethWrapped stETH (WSTETH) $ 2,702.38
    • bitcoin-cashBitcoin Cash (BCH) $ 449.28
    • suiSui (SUI) $ 2.49
    • leo-tokenLEO Token (LEO) $ 9.06
    • chainlinkChainlink (LINK) $ 11.68
    • stellarStellar (XLM) $ 0.229938
    • usdsUSDS (USDS) $ 0.999775
    • avalanche-2Avalanche (AVAX) $ 16.69
    • whitebitWhiteBIT Coin (WBT) $ 48.22
    • the-open-networkToncoin (TON) $ 2.74
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999793
    • shiba-inuShiba Inu (SHIB) $ 0.000011
    • litecoinLitecoin (LTC) $ 80.09
    • wethWETH (WETH) $ 2,241.37
    • wrapped-eethWrapped eETH (WEETH) $ 2,398.88
    • hedera-hashgraphHedera (HBAR) $ 0.135619
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • moneroMonero (XMR) $ 303.20
    • polkadotPolkadot (DOT) $ 3.17
    • bitget-tokenBitget Token (BGB) $ 4.07
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 101,345.00
    • pi-networkPi Network (PI) $ 0.506562
    • uniswapUniswap (UNI) $ 6.28
    • pepePepe (PEPE) $ 0.000009
    • daiDai (DAI) $ 0.999813
    • aaveAave (AAVE) $ 228.89
    • okbOKB (OKB) $ 53.18
    • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • bittensorBittensor (TAO) $ 306.87
    • aptosAptos (APT) $ 3.94
    • susdssUSDS (SUSDS) $ 1.06
    • crypto-com-chainCronos (CRO) $ 0.080698
    • internet-computerInternet Computer (ICP) $ 4.61
    • jito-staked-solJito Staked SOL (JITOSOL) $ 160.83
    • nearNEAR Protocol (NEAR) $ 1.91
    • ethereum-classicEthereum Classic (ETC) $ 15.20