Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

Ledger ConnectKit Library Compromised with a Drainer, Posing Security Risks to Web3 Apps

Altszn.com by Altszn.com
December 14, 2023
in Metaverse, Web3
0
Ledger ConnectKit Library Compromised with a Drainer, Posing Security Risks to Web3 Apps
400
SHARES
2.4k
VIEWS
Share on FacebookShare on Twitter

[ad_1]

by Nik Asti

Published: December 14, 2023 at 8:48 am Updated: December 14, 2023 at 8:48 am

by Victor Dey

Edited and fact-checked:
December 14, 2023 at 8:48 am

To improve your local-language experience, sometimes we employ an auto-translation plugin. Please note auto-translation may not be accurate, so read original article for precise information.

In Brief

The breach of Ledger’s ConnectKit library, which replaced the legitimate tool with a drainer script, exposed numerous Web 3.0 apps.

Ledger ConnectKit Library Compromised, Posing Security Risks to Web 3.0 Applications

A security breach occurred in the Web3 sphere, compromising the Ledger ConnectKit library, crucial for linking Ledger Live with applications. This hack involves the replacement of the library with a ‘drainer’ script, posing a serious threat to user funds.

The compromised package, ConnectKit —- automatically loads a JavaScript script from cdn.jsdelivr.net, which includes a drainer, into the global scope.

This infiltration made the frontend of applications using this library vulnerable, particularly after user authorization. Reports indicate that attackers have altered the wallet connection modal window, putting all wallet owners at risk, not just those using Ledger Live.

🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨

A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.

Your Ledger device and…

— Ledger (@Ledger) December 14, 2023

Warnings Issued by Ledger Security

Notable cryptocurrency security experts, including banteg, have confirmed the Ledger library’s compromise and are advising against interactions with any decentralized applications (dApps) until more clarity emerges. The vulnerability appears to also affect the ledger connect-kit-loader, as it specifies the dependency loosely.

The attack potentially impacts a wide range of parties, as indicated by a list of affected libraries and applications using the @ledgerhq/connect-kit. Ledger’s suggestion to use connect-kit loader for loading connect-kit exacerbates the issue, as even pinned versions of the loader fetch the latest version of connect-kit, leading to widespread infiltration.

🚨 ledger library confirmed compromised and replaced with a drainer. wait out interacting with any dapps till things become clearer.https://t.co/xapunW8zC3 pic.twitter.com/NlAc11vhdv

— banteg (@bantg) December 14, 2023

Attackers have managed to compromise a significant number of libraries by targeting just the connect-kit. Ledger identifies version 1.1.4 as the last known safe release, but considers all releases up to 1.1.7, posted on the day of the attack, as compromised.

This security incident underscores the critical importance of robust cybersecurity measures in the rapidly evolving Web 3.0 domain, where even well-established tools like Ledger’s library are not immune to sophisticated cyber attacks.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Nik is an accomplished analyst and writer at Metaverse Post, specializing in delivering cutting-edge insights into the fast-paced world of technology, with a particular emphasis on AI/ML, XR, VR, on-chain analytics, and blockchain development. His articles engage and inform a diverse audience, helping them stay ahead of the technological curve. Possessing a Master’s degree in Economics and Management, Nik has a solid grasp of the nuances of the business world and its intersection with emergent technologies.

More articles

Nik Asti



Nik is an accomplished analyst and writer at Metaverse Post, specializing in delivering cutting-edge insights into the fast-paced world of technology, with a particular emphasis on AI/ML, XR, VR, on-chain analytics, and blockchain development. His articles engage and inform a diverse audience, helping them stay ahead of the technological curve. Possessing a Master’s degree in Economics and Management, Nik has a solid grasp of the nuances of the business world and its intersection with emergent technologies.



More articles



[ad_2]

Read More: mpost.io

Tags: appsCompromisedConnectKitdrainerLedgerLibraryMetaverseposingRisksSecurityWeb3
ADVERTISEMENT

Recent

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025
U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

U.S. Lawmakers Unveil CLARITY Act Regulating Digital Assets

June 10, 2025

Categories

  • Blockchain (3,943)
  • Crypto (3,943)
  • Dark Web (11)
  • DeFi (3,943)
  • Ethereum (2,447)
  • Metaverse (2,370)
  • Monero (14)
  • Solana (1,856)
  • Web3 (9,485)
  • Zcash (165)

Category

Advertise

Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

Useful Links

Advertise
DMCA
Contact Us
Privacy Policy
Shipping & Returns
Terms of Use

Resources

Exchanges
Changelly
Web3 Jobs

Recent News

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

VIRTUAL Rallies Ahead of First Ethereum-Based AI Agent Launch

June 15, 2025
Is it the future of finance?

Is it the future of finance?

June 15, 2025

© 2022 Altszn.com. All Rights Reserved.

No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3

© Altszn.com. All Rights Reserved.

  • origyn-foundationORIGYN (OGY) $ 0.000839
  • origyn-foundationORIGYN (OGY) $ 0.000839
  • meta-platforms-ondo-tokenized-stockMeta Platforms (Ondo Tokenized Stock) (METAON) $ 595.11
  • meta-platforms-ondo-tokenized-stockMeta Platforms (Ondo Tokenized Stock) (METAON) $ 595.11
  • wolf-2WOLF (WOLF) $ 0.006845
  • wolf-2WOLF (WOLF) $ 0.006845
  • marcopoloMAP Protocol (MAPO) $ 0.001103
  • australian-safe-shepherdAustralian Safe Shepherd (ASS) $ 0.00000000
  • marcopoloMAP Protocol (MAPO) $ 0.001103
  • australian-safe-shepherdAustralian Safe Shepherd (ASS) $ 0.00000000
  • treehouseTreehouse (TREE) $ 0.043671
  • treehouseTreehouse (TREE) $ 0.043671
  • anyswapAnyswap (ANY) $ 0.516433
  • anyswapAnyswap (ANY) $ 0.516433
  • scorScor (SCOR) $ 0.015097
  • pulsechain-bridged-weth-pulsechainPulsechain Bridged WETH (Pulsechain) (WETH) $ 2,259.44
  • scorScor (SCOR) $ 0.015097
  • pulsechain-bridged-weth-pulsechainPulsechain Bridged WETH (Pulsechain) (WETH) $ 2,259.44
  • foomFoom (FOOM) $ 0.00000004
  • foomFoom (FOOM) $ 0.00000004
  • coinbase-ondo-tokenized-stockCoinbase (Ondo Tokenized Stock) (COINON) $ 155.61
  • wink-2WINK (WINK) $ 0.029850
  • coinbase-ondo-tokenized-stockCoinbase (Ondo Tokenized Stock) (COINON) $ 155.61
  • wink-2WINK (WINK) $ 0.029850
  • coq-inuCoq Inu (COQ) $ 0.00000010
  • coq-inuCoq Inu (COQ) $ 0.00000010
  • peercoinPeercoin (PPC) $ 0.223229
  • peercoinPeercoin (PPC) $ 0.223229
  • solomonSolomon (SOLO) $ 0.591592
  • solomonSolomon (SOLO) $ 0.591592
  • akedoAkedo (AKE) $ 0.000295
  • akedoAkedo (AKE) $ 0.000295
  • xplaCONX (CONX) $ 0.007200
  • equitedgeEquitEdge (EEG) $ 0.019363
  • xplaCONX (CONX) $ 0.007200
  • equitedgeEquitEdge (EEG) $ 0.019363
  • bella-protocolBella Protocol (BEL) $ 0.084080
  • mazaMaza (MZC) $ 0.003045
  • bella-protocolBella Protocol (BEL) $ 0.084080
  • mazaMaza (MZC) $ 0.003045
  • ethichubEthix (ETHIX) $ 0.095060
  • lisk-bridged-wsteth-liskLisk Bridged wstETH (Lisk) (WSTETH) $ 2,777.63
  • ethichubEthix (ETHIX) $ 0.095060
  • lisk-bridged-wsteth-liskLisk Bridged wstETH (Lisk) (WSTETH) $ 2,777.63
  • puffer-financePuffer (PUFFER) $ 0.014524
  • puffer-financePuffer (PUFFER) $ 0.014524
  • world-assetsWorldAssets (INC) $ 0.073507
  • world-assetsWorldAssets (INC) $ 0.073507
  • hairdaoHairDAO (HAIR) $ 9.44
  • hairdaoHairDAO (HAIR) $ 9.44
  • public-meme-tokenPublic Masterpiece Token (PMT) $ 0.106413
  • public-meme-tokenPublic Masterpiece Token (PMT) $ 0.106413
  • apple-xstockApple xStock (AAPLX) $ 307.96
  • apple-xstockApple xStock (AAPLX) $ 307.96
  • milady-cult-coinMilady Cult Coin (CULT) $ 0.000141
  • milady-cult-coinMilady Cult Coin (CULT) $ 0.000141
  • midas-rockaway-market-neutralMidas Rockaway Market Neutral (MROX) $ 1.13
  • kofi-aptosKofi Aptos (KAPT) $ 1.03
  • midas-rockaway-market-neutralMidas Rockaway Market Neutral (MROX) $ 1.13
  • kofi-aptosKofi Aptos (KAPT) $ 1.03
  • aism-faith-tokenAISM FAITH TOKEN (AISM) $ 0.006573
  • wrapped-monadWrapped MON (WMON) $ 0.017878
  • aism-faith-tokenAISM FAITH TOKEN (AISM) $ 0.006573
  • wrapped-monadWrapped MON (WMON) $ 0.017878
  • overtimeOvertime (OVER) $ 0.114696
  • overtimeOvertime (OVER) $ 0.114696
  • vidaioVidaio (SN85) $ 1.62
  • vidaioVidaio (SN85) $ 1.62
  • metronomeMetronome (MET) $ 0.745315
  • metronomeMetronome (MET) $ 0.745315
  • spacechain-erc-20SpaceChain (ERC-20) (SPC) $ 0.016172
  • spacechain-erc-20SpaceChain (ERC-20) (SPC) $ 0.016172
  • biliraBiLira (TRYB) $ 0.021490
  • biliraBiLira (TRYB) $ 0.021490
  • gitcoinGitcoin (GTC) $ 0.074401
  • avalanche-bridged-dai-avalancheAvalanche Bridged DAI (Avalanche) (DAI) $ 1.00
  • gitcoinGitcoin (GTC) $ 0.074401
  • avalanche-bridged-dai-avalancheAvalanche Bridged DAI (Avalanche) (DAI) $ 1.00
  • i-love-puppiesI love puppies (PUPPIES) $ 0.00000015
  • i-love-puppiesI love puppies (PUPPIES) $ 0.00000015
  • xeqm-labsXEQM Labs (XEQM) $ 0.023390
  • xeqm-labsXEQM Labs (XEQM) $ 0.023390
  • airtor-protocolANyONe Protocol (ANYONE) $ 0.081143
  • airtor-protocolANyONe Protocol (ANYONE) $ 0.081143
  • swarmsSwarms (SWARMS) $ 0.006472
  • doge-lumensDogeLumens (DXLM) $ 0.000053
  • swarmsSwarms (SWARMS) $ 0.006472
  • doge-lumensDogeLumens (DXLM) $ 0.000053
  • bitcoin-limited-editionBitcoin Limited Edition (BTCLE) $ 415.97
  • sx-network-2SX Network (SX) $ 0.013459
  • bitcoin-limited-editionBitcoin Limited Edition (BTCLE) $ 415.97
  • sx-network-2SX Network (SX) $ 0.013459
  • kpk-usdc-primekpk USDC Prime (KPK USDC P) $ 1.01
  • destra-networkDestra Network (DSYNC) $ 0.006509
  • kpk-usdc-primekpk USDC Prime (KPK USDC P) $ 1.01
  • destra-networkDestra Network (DSYNC) $ 0.006509
  • grinGrin (GRIN) $ 0.027716
  • grinGrin (GRIN) $ 0.027716
  • amoAMO Coin (AMO) $ 0.000304
  • amoAMO Coin (AMO) $ 0.000304