Warning - Ledger users should stop using crypto web apps until investigations into a potential cybersecurity incident is complete
News sites are reporting that there are notices of malicious code that was shared on social media Thursday morning. The code was found in software libraries for Ledger’s ConnectKit, which connects blockchain apps with Ledger devices.
Blockworks has stated that so far at least $150,000 has been lost as a result of the malicious code slipping into websites in production. The good news is Ledger users are not at risk if they refrain from transacting. However, the extent of the hack is not known at this time as many websites are still affected and users are getting hit which means it will be some time before we know the true impact.
Decentralized exchange SushiSwap took its front-end web app offline soon after the warnings. In a statement they said,
“We’ve identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps. If you have the Sushi page open and see an unexpected ‘Connect Wallet’ pop-up, DO NOT interact or connect your wallet. We’re actively working to remove the ledger wallet connector. For your safety, please refrain from engaging with any dApps until further notice. Stay tuned for updates.”
Ledger’s official X account initially confirmed the potential attack and said the company had removed the malicious code. They went on to say the malicious version of the file was replaced with the genuine version. It will take some time for this code to populate. So out of an abundance of caution, I'd recommend taking a pause until the full report is published and the true all clear is sounded.