Ledger experiences major security breach, numerous DApps affected, SlowMist: Do not operate, wait for updates from all parties
Table of Contents
Table of Contents
Ledger Module Hijacked
Cybersecurity firm SlowMist's founder, Yu Xian, tweeted on the evening of the 14th that the Ledger module was hijacked in the supply chain and tampered with. Many DApps rely on the affected Ledger Connect Kit. The extent of the impact is not yet clear, and users should exercise caution when executing DApp operations.
Frontends including Balancer, Zapper, and Sushi are affected. Permission querying tool Revoke.cash has temporarily shut down its website.
Ledger 的一个模块被供应链劫持篡改了,特别注意下这个风险,主要是不知道影响面多广,可能不少 DApp 都有依赖 Ledger 被投毒的库 ledgerhq/connect-kit。大家警惕下所有 DApp 相关操作,注意钱包待签名的请求信息是不是预期内的。 https://t.co/rg06suM793
— Cos(余弦)😶🌫️ (@evilcos) December 14, 2023
Ledger: Delete Malicious Versions, Avoid Interacting with Any DApp Temporarily
In a subsequent tweet, Ledger stated that they have identified and removed the malicious versions of the Ledger Connect Kit. They advised users to avoid interacting with any DApp temporarily. Ledger hardware devices and Ledger Live are not affected, and a comprehensive incident report will be provided later.
🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨
A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.
Your Ledger device and…
— Ledger (@Ledger) December 14, 2023
MetaMask: Will Release Fix
MetaMask recommends users to download and enable the Blockaid extension in response to this incident. The MetaMask Portfolio team has devised a fix that will be released shortly.
If you’re a MetaMask user: Please ensure that you have the Blockaid feature turned on in MetaMask Extension before performing any transactions on MetaMask Portfolio. The MetaMask Portfolio team is on it and has a fix in place that will be rolled out today.
— MetaMask 🦊🫰 (@MetaMask) December 14, 2023
Yu Xian mentioned that the repair efforts from all parties are faster than expected, and the crisis should have subsided. However, he also advised that it is best to refrain from any operations at the moment and wait quietly for the repairs to be completed.
Related
- Is Uniswap Governance a Shell? DAO Representative Accuses Uniswap of Unveiling Unichain Without Their Knowledge
- $20 Million Backing for Web3 Startup! Movement Labs Teams Up with Gate to Drive Cross-Chain Compatibility
- Aave Labs proposes integrating the tokenized fund BUIDL by BlackRock to enhance the efficiency of the GHO stability module.