Ledger Exploit Exposes DeFi Vulnerabilities and Raises Concerns in Crypto Community

Hackers exploited a malicious code inserted into the Github library for Ledger's Connect Kit, a widely-used blockchain software, stealing $484,000 and impacting several major decentralized finance (DeFi) protocols. Ledger confirmed that an employee was targeted in a phishing attack, resulting in the publication of the malicious code. Users have been warned to avoid using dApps until the protocols are updated. While Ledger has removed the malicious version, every protocol using Connect Kit must manually update their library to mitigate the risk. The hack highlights the vulnerability of decentralized applications and the potential points of failure in the supply chain.
- Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code CoinDesk
- 'Wallet drainer' code added to Ledger library has crypto on edge Blockworks
- Ledger Exploit Endangers DeFi; Sushi Says 'Do Not Interact With ANY dApps' CoinDesk
- Ledger patches vulnerability after multiple DApps using connector library were compromised Cointelegraph
- Crypto hacks and chaos aren’t halting this holiday season TechCrunch
Reading Insights
0
0
2 min
vs 3 min read
79%
469 → 99 words
Want the full story? Read the original article
Read on CoinDesk