Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»EXCHANGE NEWS»Aftermath: How did The Ledger Hacker’s $484,000 heist happen?
EXCHANGE NEWS

Aftermath: How did The Ledger Hacker’s $484,000 heist happen?

By Crypto FlexsDecember 16, 20233 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Aftermath: How did The Ledger Hacker’s 4,000 heist happen?
Share
Facebook Twitter LinkedIn Pinterest Email

As reported yesterday. Hackers launched a sophisticated attack targeting users of popular Web3 apps such as Zapper, SushiSwap, and Phantom, stealing approximately $484,000 in cryptocurrency funds. The attack focused on Ledger’s Connect Kit, a code library that enables connections between cryptocurrency wallets and decentralized apps.


key point

  • Ledger’s Connect Kit was compromised in a malicious attack, resulting in the theft of approximately $484,000 in funds.
  • The attackers used a phishing attack to gain access to a former Ledger employee’s account and inject malicious code.
  • Malware was distributed when apps such as Zapper, SushiSwap, and Phantom were updated with compromised Connect Kit code.
  • The malware tricked users into authorizing transactions to the attacker’s address rather than the intended app.
  • Ledger has now disabled the malware and declared the Connect Kit safe to use again, but called for continued efforts in signing transactions.

Hackers were able to access a former Ledger employee’s account on the node package manager platform NPMJS through a phishing attack. From this vantage point, the attackers injected malicious code into GitHub’s Ledger Connect Kit update. When vulnerable apps were updated to a compromised Connect Kit version, malware was distributed to unwitting users’ browsers.

Today’s security incident appears to be the culmination of three separate failures at Ledger.

1. Blindly load code without locking in a specific version and checksum.
2. We do not enforce the “two-person rule” when it comes to code review and deployment.
3. We do not revoke access from former employees.

— Jameson Lopp (@lopp) December 14, 2023

The malware allowed the hackers to trick users into approving transactions that would send funds to the attacker’s wallet rather than the intended app.

According to blockchain security platform Cybers, the code likely manipulates transaction data to trick users into confirming payments they don’t fully understand. For example, a user who authorized a token payment to activate an app feature may instead see the payment as authorized to the hacker’s address.

The exact techniques used require further analysis, but it is clear that the attack relied on clever social engineering to induce user error. Ledger and security experts recommend constant caution when approving cryptocurrency transactions and carefully reviewing addresses and details, even when an app appears legitimate.

It seems that after absorbing nearly half a million exploits, the hackers decided to stop working for fear of growing interest. Ledger was able to disable the malware and has now declared the Connect Kit safe for use once again.

However, the fact that these attacks easily compromised the critical infrastructure of popular apps sends a sobering warning to the Web3 community.

As the industry continues to work diligently to increase security and transparency for transactions, remembering the human element will be key.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bull and Bear Scenarios for XRP That Could Happen in November

November 26, 2025

Whale sells 190 million Ripple, Binance Coin loses steam, Digitap gains bullish momentum through utility-based growth.

November 23, 2025

Bitcoin Policy Institute Launches Interactive US Tax Payment Model to Support Bitcoin For America Act

November 20, 2025
Add A Comment

Comments are closed.

Recent Posts

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025

Mantle And Bybit Unite To Bring USDT0, The Omnichain Deployment Of Tether’s USDT Stablecoin, To The Largest Exchange-Related Network

November 27, 2025

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025

Technance Introduces Institutional-Grade Infrastructure For Exchanges, Fintech Platforms, And Web3 Applications

November 27, 2025

Investors Eye 900× ROI Potential as Ozak AI Continues Record Presale Momentum

November 27, 2025

Korea’s Upbit reports $36 million loss due to Solana hot wallet breach

November 27, 2025

Bitcoin remains stable as Texas allocates $5 million to BlackRock’s IBIT.

November 26, 2025

Bull and Bear Scenarios for XRP That Could Happen in November

November 26, 2025

Quantum-secure data storage for app developers with open source Shamir secret sharing for capacitors

November 26, 2025

Bybit’s 7th Anniversary Shares A $2.5 Million Thank-You With Nearly 80 Million Traders Worldwide

November 26, 2025

MEXC Launches Year-End Golden Era Showdown With 2,000g Gold Bar And BTC From 10 Million USDT Prize Pool

November 26, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025

Mantle And Bybit Unite To Bring USDT0, The Omnichain Deployment Of Tether’s USDT Stablecoin, To The Largest Exchange-Related Network

November 27, 2025

A Retired Italian Couple Earns $998 Per Day Passively Through 8hoursmining Cloud Cryptocurrency Mining.

November 27, 2025
Most Popular

Summary of the CIAN yield hierarchy

February 27, 2025

Coinbase donates $3.6 million to fund Bitcoin developers through Brink.

February 16, 2024

OKX introduces mandatory risk perception questionnaire for UK users

January 4, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.