News Report Software Technology

The integrity of Ledger's ConnectKit Library has been breached, leading to serious implications for the safety of Web 3.0 applications.

In Brief

The Ledger ConnectKit library faced a security breach that compromised its integrity, substituting the genuine library with a malicious script that jeopardized various Web3 applications.

The Ledger's ConnectKit Library has been compromised, raising alarms regarding the security of Web 3.0 applications.

A security incident has impacted the Web3 space, affecting the library essential for connecting Ledger Live with other applications. This hack involves the substitution of the library with a malicious drainer script, posing a significant risk to users' funds. Ledger ConnectKit The compromised ConnectKit package automatically loads a harmful JavaScript script from cdn.jsdelivr.net, which includes a draining component, into the global scope.

This breach has rendered the frontend of applications using this library vulnerable, particularly after users have authorized their transactions. Reports suggest that attackers have tampered with the wallet connection interface, endangering all wallet holders, not just those utilizing specific services.

🚨 We've successfully identified and eliminated the malicious version of the Ledger Connect Kit. 🚨 Ledger Live .

Warnings Issued by Ledger Security

This attack could potentially affect a wide range of stakeholders, as evidenced by a list of compromised libraries and applications utilizing the service. Ledger's recommendation to use the connect-kit loader for loading connect-kit complicates matters, as even pinned versions of the loader fetch the latest version of connect-kit, facilitating extensive infiltration. dApps 🚨 The Ledger library has been confirmed compromised, and has been replaced with a malicious drainer. It’s advised to hold off on interacting with any dapps until the situation clarifies.

The attackers have been successful in compromising a notable number of libraries simply by targeting the connect-kit. Ledger indicates that version 1.1.4 is the last verified safe version, while considering all versions up to 1.1.7, released on the day of the breach, as vulnerable. @ledgerhq/connect-kit This security incident highlights the urgent need for strong cybersecurity measures in the rapidly advancing Web 3.0 environment, which is not immune to advanced cyber threats even for established tools like Ledger’s library.

Nik is a skilled analyst and writer at Metaverse Post, known for providing cutting-edge insights into the dynamic tech scene, particularly focusing on AI/ML, XR, VR, on-chain analytics, and blockchain innovation. His writing captures the attention of a diverse audience, assisting them in staying abreast of technological advancements. With a Master’s degree in Economics and Management, Nik possesses a deep understanding of the business landscape and its convergence with innovative technologies.

Cryptocurrencylistings.com has rolled out CandyDrop to streamline the acquisition of cryptocurrencies and enhance user interaction with quality projects.

Disclaimer

In line with the Trust Project guidelines DeFAI must address the challenges of cross-chain connectivity to realize its full potential.

AI is manifesting in various forms within the healthcare sector, contributing to advancements like uncovering new genetic insights and enabling robotic surgery technologies.

Copyright, Permissions, and Linking Policy

Know More

The Ledger ConnectKit library has been breached by a malicious actor, resulting in significant security threats to various Web3 applications, as reported by Metaverse Post.

The recent breach of Ledger's ConnectKit library involved replacing the original tool with a harmful script designed to siphon off funds, thereby endangering multiple Web3 apps in the process.

Know More
Read More
Read more
News Report Technology
Raphael Coin is set to debut, bringing a masterpiece from the Renaissance era into the blockchain realm.
News Report Technology
Examining how cryptocurrency initiatives are being leveraged for philanthropic endeavors.
News Report Technology
Let’s delve into projects that are utilizing digital currencies to support charitable causes.
Art News Report Technology
In 2024, AI is set to revolutionize healthcare, playing roles from discovering new genetic links to enhancing robotic surgical systems.