Unable to load image

Cryptocels BTFO again: Ledger's NPM account has been hacked | Hacker News

https://news.ycombinator.com/item?id=38641211

https://i.rdrama.net/images/17025729325024972.webp

https://twitter.com/zachxbt/status/1735292040986886648

https://i.rdrama.net/images/17025732201000707.webp

https://twitter.com/paoloardoino/status/1735315976827101274

Abridged summary from Ledger themselves:

  • This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account.

  • The attacker published a malicious version of the Ledger Connect Kit (affecting versions 1.1.5, 1.1.6, and 1.1.7). The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet.

  • Ledger's technology and security teams were alerted and a fix was deployed within 40 minutes of Ledger becoming aware. The malicious file was live for around 5 hours, however we believe the window where funds were drained was limited to a period of less than two hours.

  • The genuine and verified Ledger Connect Kit version 1.1.8 is now propagating and is safe to use.

  • For builders who are developing and interacting with the Ledger Connect Kit code: connect-kit development team on the NPM project are now read-only and can't directly push the NPM package for safety reasons.

  • We have internally rotated the secrets to publish on Ledger's GitHub.

  • Ledger, along with Walletconnect and our partners, have reported the bad actor's wallet address. The address is now visible on chainalysis

  • Tether_to has frozen the bad actor's USDT.

  • We are actively talking with customers whose funds might have been affected, and working proactively to help those individuals at this time.

  • We are filing a complaint and working with law enforcement on the investigation to find the attacker.

  • We're studying the exploit in order to avoid further attacks. We believe the attacker's address where the funds were drained is here: 0x658729879fca881d9526480b82ae00efc54b5c2d

https://twitter.com/Ledger/status/1735326240658100414

51
Jump in the discussion.

No email address required.

Crypto is great. We don't need to test an ancap society in a real world, we can just check what's happening in crypto as a clue what it'll be like

Jump in the discussion.

No email address required.

>people who use NPM get punished severely

:#marseyancap:

Jump in the discussion.

No email address required.

:marseysad:

Jump in the discussion.

No email address required.

Do you think the Fed's erection grows every time a crypto company comes running to them?

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

So even if you use a hardware wallet your crypto isn't safe I guess. :marseyshrug:

You basically need to know everything about both the blockchain and cybersecurity in order to hold onto your crypto at this point.

Jump in the discussion.

No email address required.

Tbh a lot of the complexity and danger in crypto currently comes from trying to make cryptocurrency do non-currency things

Jump in the discussion.

No email address required.

or just use a normal, open source crypto wallet like bitcoin-qt or whatever

Jump in the discussion.

No email address required.

this is good for bitcoin


Follower of Christ :marseyandjesus: Tech lover, IT Admin, heckin pupper lover and occasionally troll. I hold back feelings or opinions, right or wrong because I dislike conflict.

Jump in the discussion.

No email address required.

Ah the next chapter in "Everything is this the users fault"! I bet those hacked users didn't have their ledger wrapped in tin foil like step 81 of 101 in the manual says to. Losers deserved to lose their money.

Jump in the discussion.

No email address required.

Look, it's very simple: not your code, not your keys, not your coins.

If you can't be bothered to read 1M lines of janky JavaScript and associated dependencies, why are you in crypto?

Jump in the discussion.

No email address required.

i got a trezor this week, so feeling good about that judgement call :marseysmug2:

Jump in the discussion.

No email address required.

I know what most of these words mean

Jump in the discussion.

No email address required.

:#reindeer:

Snapshots:

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.