[ccpw id="39382"]

HomeCrypto NewsMarketLedger Discloses Update and Timeline of the Recent Wallet Security Breach

Ledger Discloses Update and Timeline of the Recent Wallet Security Breach

Date:

Written By:

Follow TheCryptoBasic

Ledger, the crypto hardware wallet manufacturer, has disclosed an update and timeline for the recent security breach affecting its Connect Kit tool.

The security breach, which occurred yesterday, has raised questions about Ledger’s security practice. To allay these concerns and keep the community updated, the company shared a recap and an update on X, explaining the cause and the impact of the breach and the actions they took to fix it.

Timeline of the Ledger Breach

Ledger said that the breach started when a hacker got access to the NPMJS account of a former employee through a phishing attack. NPMJS is a platform that hosts code packages for developers. The crypto community has questioned why a former employee still has access to the company’s code.

- Advertisement -

After gaining access to the NPMJS, the hacker then uploaded a malicious version of the Ledger Connect Kit library. The Connect Kit is a tool that allows users to connect their hardware wallets to web browsers and other platforms. 

As a result, the exploit affected DeFi protocols that use this tool, including MetaMask, Lido, and Sushi. The malicious code used a fake WalletConnect to send funds to the hacker’s wallet. 

Any user who tried to connect to these DeFi protocols fell victim to the exploit. On-chain surveillance system Lookonchain revealed that, as of 14:44 (UTC) yesterday, the hacker had stolen about $484K worth of cryptocurrencies from several users.

However, it bears mentioning that the exploit did not in any way affect user funds stored on Ledger. Ledger CEO and Chairman Pascal Gauthier confirmed this in a letter yesterday. Users were advised to keep their assets on their Ledger and not interact with any dApp.

According to the Ledger team, theyiscovered and fixed the issue within 40 minutes. They confirmed that the malicious file was up for about 5 hours, but the movement of stolen funds occurred in the space of 2 hours. 

What Next?

The firm revealed that they also worked with WalletConnect to shut down the fake project. The company then released a safe and verified version of the Ledger Connect Kit, 1.1.8, and advised users to wait 24 hours before using it again.

To enhance security against future attacks, Ledger made the connect-kit development team for the NPM project read-only and updated the secrets for publication on Ledger’s GitHub repository.

The company also reminded users to always clear sign with their Ledger devices. Clear signing involves checking all the transaction details on the screen before approving. For blind signing, Ledger suggests using an additional Ledger mint wallet or manually parsing the transaction.

Ledger, along with WalletConnect and other partners, reported the hacker’s wallet address to Chainalysis, a blockchain analysis company, and Tether. Tether’s CEO Paolo Ardoino disclosed that Tether had frozen the hacker’s USDT.

According to Ledger, they are also talking to the customers who might have lost funds to help them. The company revealed that they are filing a complaint and working with law enforcement to find the hacker. Ledger is also studying the breach to avoid future exploits.

DisClamier: This content is informational and should not be considered financial advice. The views expressed in this article may include the author's personal opinions and do not reflect The Crypto Basic opinion. Readers are encouraged to do thorough research before making any investment decisions. The Crypto Basic is not responsible for any financial losses.

Author

Sam Wisdom Raphael
Sam Wisdom Raphael
Sam Wisdom Raphael is a seasoned crypto news writer and journalist with 5 years of experience covering blockchain, DeFi, and crypto developments. Sam's active presence in the crypto community complements his deep understanding of the crypto space, allowing him to craft comprehensible price analysis reports and tackle technical blockchain concepts.

More from Author

Latest Stories

Here are Ethereum Price Scenarios as ETH Sees $512.38M Net Inflow

Ethereum sees over $500M net futures flows, recording bullish momentum as price tests key resistance levels. Ethereum (ETH) is currently trading at $3,158, reflecting a...

Here are Next Cardano Resistance Levels as $1.65M in Positions Face Liquidation

Cardano tests key resistance levels with significant liquidation data showing pressure on long positions. Cardano (ADA) is currently trading at $0.4316, reflecting a 3.3% gain...

IG’s Chief Analyst Expects Bitcoin to Recover Upon This Week’s Fed Rate Cut

Bitcoin and the broader crypto market continue to face a difficult stretch, yet IG's Chief Market Analyst Chris Beauchamp says a turnaround may already...

Can Bitcoin Reach $125K After Testing and Breaking 20-Day SMA?

Bitcoin is testing key resistance levels after breaking the 20-day SMA, with analysts expecting potential upside momentum. Currently, Bitcoin is trading at $91,747, reflecting a...

Here are Ethereum Price Scenarios as ETH Sees $512.38M Net Inflow

Ethereum sees over $500M net futures flows, recording bullish momentum as price tests key resistance levels. Ethereum (ETH) is currently trading at $3,158, reflecting a...

Ethereum Bounces Off Key Weekly Support: Here’s Its Next Possible Direction

Ethereum rebounds above a major weekly support as volatility rises, with traders watching higher resistance levels for direction. Notably, Ethereum is trading at $3,164.58, showing...

Market Expert Reveals 3 Reasons XRP Failed to Pump in 2025

A well-known market commentator has shared three reasons XRP failed to deliver the pump many expected in 2025. XRP entered 2025 with huge expectations after...

Top CEO Shares How Much XRP Could Still Drop, Reveals Forces Behind Crypto Market Struggles

A crypto market analyst and trader has projected how much lower XRP could still drop from here, identifying what he believes is behind the...

Shiba Inu Back at the Same Level from Which It Surged 1,237% in 2021

Historical context supports an analysis suggesting that Shiba Inu could explode from here as it retests a crucial support area. Notably, the analysis came from...

Shiba Inu Price Outlook for 2026: Is $0.0001 Within Reach for SHIB? 

With only a few weeks left before the end of 2025, Shiba Inu community members are now considering whether SHIB might reach $0.0001 next...

Dogecoin Faces Rejection at $0.153 But TD Sequential Says Buy

Dogecoin faces rejection at the middle Bollinger Band, but the meme coin's TD Sequential signals a potential buying opportunity. Dogecoin (DOGE) has dropped by 0.6%...

Dogecoin Rebounds from Swing Lows: Here are Upside Fib Targets to Watch

Dogecoin tests key resistance as intraday rebound meets Fib ceilings while MACD bullish cross setup forms. Notably, Dogecoin (DOGE) is posting modest gains today, trading...

Guides