{"id":61687,"date":"2023-12-14T15:07:44","date_gmt":"2023-12-14T15:07:44","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/12\/14\/supply-chain-attack-targeting-ledger-crypto-wallet-leaves-users-hacked-techcrunch\/"},"modified":"2023-12-14T15:07:44","modified_gmt":"2023-12-14T15:07:44","slug":"supply-chain-attack-targeting-ledger-crypto-wallet-leaves-users-hacked-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/12\/14\/supply-chain-attack-targeting-ledger-crypto-wallet-leaves-users-hacked-techcrunch\/","title":{"rendered":"Supply chain attack targeting Ledger crypto wallet leaves users hacked | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\">Hackers compromised the code behind a crypto protocol used by multiple web3 applications and services, the software maker Ledger said on Thursday.<\/p>\n<p>Ledger, a company that makes a widely used and popular crypto hardware and software wallet, among other products, announced on X (previously Twitter) that <a href=\"https:\/\/twitter.com\/Ledger\/status\/1735291427100455293\" target=\"_blank\" rel=\"noopener\">someone had pushed out a \u201cmalicious version\u201d of its Ledger Connect Kit<\/a>, a library that decentralized apps (dApps) made by other companies and projects use to connect to the Ledger wallet service.<\/p>\n<p>\u201cA genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves,\u201d Ledger wrote.<\/p>\n<p>Soon after, Ledger <a href=\"https:\/\/twitter.com\/Ledger\/status\/1735298142118072512\" target=\"_blank\" rel=\"noopener\">posted an update<\/a> saying that the hackers had replaced the genuine version of its software some six hours earlier, and that the company was investigating the incident and would \u201cprovide a comprehensive report as soon as it\u2019s ready.\u201d<\/p>\n<p>Ledger spokesperson Phillip Costigan did not provide any comments beyond what the company posted on its official X account.<\/p>\n<p>The company says <a href=\"https:\/\/www.ledger.com\/the-company\" target=\"_blank\" rel=\"noopener\">it has sold six million units<\/a> of its hardware wallet, and Ledger Live, its software equivalent, is used by 1.5 million users. The Ledger hardware wallet is not believed to be affected by the hack.<\/p>\n<p>Tal Be\u2019ery, the co-founder of crypto wallet ZenGo, told TechCrunch that the hackers essentially pushed out a malicious version of the software that was designed to trick users into connecting their wallets and assets to the malicious version of the software.<\/p>\n<p><h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\tDo you have more information about this hack? We\u2019d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email lorenzo@techcrunch.com. You also can contact TechCrunch via SecureDrop.\t<\/p>\n<p>That would allow the hackers to drain the crypto inside users\u2019 wallets \u2014 so long as the users accepted the push to connect their wallets to the malicious Ledger version.<\/p>\n<p>It\u2019s not immediately clear how many people fell victim to the hack. ZachXBT, a well-known independent crypto researcher, <a href=\"https:\/\/twitter.com\/zachxbt\/status\/1735292040986886648\" target=\"_blank\" rel=\"noopener\">wrote on X that one victim<\/a> had more than $600,000 in crypto drained from their account.<\/p>\n<p>Several blockchain security researchers, as well as people who work in the web3 industry, warned users on social media of the supply chain hack against Ledger.<\/p>\n<p>Matthew Lilley, the chief technology officer of cryptocurrency trading platform Sushi, was one of the first ones to detect the attack and share the news.<\/p>\n<p>\u201cI would recommend never interacting with a [decentralized app] ever again and honestly just move on with your life,\u201d said Joseph Delong, the CTO of NFT lending platform AstariaXYZ, <a href=\"https:\/\/twitter.com\/josephdelong\/status\/1735293295301972022\" target=\"_blank\" rel=\"noopener\">joked on X<\/a>, referring to the fact that Ledger uses the notoriously insecure programming language Java.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2023\/12\/14\/supply-chain-attack-targeting-ledger-crypto-wallet-leaves-users-hacked\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers compromised the code behind a crypto protocol used by multiple web3 applications and services, the software maker Ledger said on Thursday. Ledger, a company that makes a widely used and popular crypto hardware and software wallet, among other products, announced on X (previously Twitter) that someone had pushed out a \u201cmalicious version\u201d of its [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61688,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-61687","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/61687","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=61687"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/61687\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/61688"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=61687"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=61687"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=61687"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}