Skip to main content

Ledger Library Exploit Alert: Users Warned Against Interacting With Dapp Front Ends Amid Wallet Drainer Risk

Ledger Library Exploit Alert: Users Warned Against Interacting With Dapp Front Ends Amid Wallet Drainer Risk

According to several reports, there’s been an alleged Ledger Connectkit Library exploit and people are being warned not to interact with decentralized application (dapp) front ends. Reportedly, the library that maintained several dapps now contains a wallet drainer.

*Editor’s Note: The end of this article was updated at 9:02 a.m. (EST) on Dec. 14, 2023, with a message from Ledger noting that the malicious file in the library was replaced and will be propagated.

Ledger Library Breach: Experts Advise Halting Dapp Usage to Dodge Wallet Drainer

A myriad of reports detail that there’s an issue with the Ledger Library as an exploit was noticed. The X user called “Banteg” explained that, “[Ledger Library] confirmed compromised and replaced with a drainer” and stressed that people should “wait out interacting with any dapps till things become clearer.”

Blockchain developer Hudson Jameson detailed that Ledger’s Library, used in numerous dapps, has been compromised, leading to the insertion of a wallet drainer. Jameson advised people to refrain from interacting with dapp front ends on websites, as the situation remains risky, especially for those unaware of the specific backend libraries in use. He added that while visiting compromised websites won’t automatically result in fund loss, deceptive browser wallet prompts could enable unauthorized asset transfers to malicious entities.

Jameson further added that Ledger is aware of the issue and actively working on a resolution. Note that safety will only be restored after affected dapps update their use of Ledger’s Web3 libraries, even post-correction by Ledger. A large swathe of other developers and crypto enthusiasts shared warnings on the social media platform X.

“I would avoid using ANY dapps until their teams confirm that they have mitigated the attack,” one individual stated. Revokecash, Zapper, Sushi, and other dapps are reportedly vulnerable to the bug, and users are being advised to avoid using these applications.

*Ledger has officially confirmed the issue. “We have identified and removed a malicious version of the Ledger Connectkit. A genuine version is being pushed to replace the malicious file now,” Ledger wrote at 8:31 a.m. (EST). “Do not interact with any dapps for the moment. We will keep you informed as the situation evolves. Your Ledger device and Ledger Live were not compromised.

“The malicious version of the file was replaced with the genuine version at around 2:35 p.m. CET. The new genuine version should be propagated soon,” Ledger added in a subsequent tweet. “We will provide a comprehensive report as soon as it’s ready. In the meantime, we’d like to remind the community to always Clear Sign your transactions – remember that the addresses and the information presented on your Ledger screen is the only genuine information. If there’s a difference between the screen shown on your Ledger device and your computer/phone screen, stop that transaction immediately.”

This story is still developing and will be updated with more information as it transpires.

What do you think about the issue with the Ledger Library? Share your thoughts and opinions about this subject in the comments section below.



from Bitcoin News https://ift.tt/Jc7kF4T

Comments

Popular posts from this blog

Deep Web Roundup: Dream Adds Monero and Bitcoin Tumbler “Chip Mixer” Launches

The darknet has been quiet of late, which is the way it’s meant to be. No news means no mega busts, honeypots, or mass market shutdowns. Even when it’s out of the spotlight though, the deep web is quietly making news, whether trialling the latest privacy coins or the newest coin mixers that promise to restore a little of the privacy that’s being stripped away from bitcoin users on a daily basis. Also read: U.S. Agency ICE Conducts Investigations That Exploit Blockchain Activity The Battle for Privacy Heats Up Privacy is all relative, but of late there’s been relatively little privacy to be enjoyed by bitcoin users. Blockchain monitoring software is becoming more sophisticated and more common, with U.S. law enforcement agencies using it to profile and hunt down deep web users. Chip Mixer is a relatively new bitcoin tumbler that’s designed to restore some of that privacy. Available on both the clearnet and darknet, the service uses a variety of techniques to obfuscate blockchain m...

International Crypto Exchange Luno Adds Bitcoin Cash Trading

Luno exchange has added bitcoin cash trading to the platform following feedback from its client base. BCH is now only the third cryptocurrency available for trading on the exchange, in addition to BTC and ETH , but more options could be on the way once Luno determines that they are credible enough. Also Read: Bitflyer Adds Bitcoin Cash Trading Across Europe and the US Luno Adds Bitcoin Cash Trading Luno, the London-headquartered company formerly known as Bitx, recently announced that bitcoin cash was made available on its cryptocurrency exchange. Starting from Monday, September 23, customers at Luno are now able to store, buy and sell BCH on the platform. The reason given for adding BCH to the exchange is feedback from users in developing markets that convinced Luno to expand their offering from previously just BTC and ETH . Marcus Swanepoel, CEO of Luno, said , “We are in a new and exciting financial era. Developing economies are leading the large-scale adoption and appli...

Ombudsman Receives Complaints About Crypto Investments in Spain

The Spanish ombudsman has been receiving complaints about cryptocurrency and how some Spanish citizens investing in these vehicles have lost everything. In his annual report, Angel Gabilondo recognized the rise of cryptocurrencies as a new problem due to the little or no regulation crypto sees in the country. In the same way, the EU has also warned about these assets recently. Spanish Ombudsman Gives His Take on Crypto Angel Gabilondo, the Spanish ombudsman, has given his take regarding cryptocurrencies and the effects they have on citizens investing in some of these projects. Gabilondo said in his yearly report that cryptocurrencies have become “a new problem” during the year examined, with many people having lost all of their funds invested. The report states : Cryptocurrency exchange companies or platforms are not regulated in the legal system, are not subject to any public supervision system, nor do they benefit from deposit guarantee systems. The affected users that sought...