Major Security Vulnerability Found in Ledger Software Library, Affecting Multiple Dapps

Major Security Vulnerability Found in Ledger Software Library, Affecting Multiple Dapps

Multiple DApps using Ledger’s connector, including Zapper, SushiSwap, Balancer and Revoke.cash, were compromised on Dec. 14.

The issue is related to a software library from Ledger wallet, the “LedgerHQ” library, that dapps rely on for use with the crypto wallet service. This vulnerability could potentially allow malicious code to be injected into numerous dapps on their front-ends, posing a significant risk to users and their assets.

Front ends to multiple dapps could be vulnerable if used. Projects like Kyber and RevokeCash confirmed on X that they disabled their front-ends.

According to latest announcement from Ledger, the malicious version of the file has been replaced with the genuine version. Ledger emphasiss that users need to always clear sign transactions, the address and the information presented on Ledger screen is the only genuine information. If there is a difference between the screen shown on your Ledger device and your computer screen, stop that transaction immediatly.

Source

Wallet

Security Incidents

Related News
Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain Bybit hackers move over half the stolen ETH onto Bitcoin, largely using ThorChain
Stablecoin neobank Infini exploited for $49 million: security analysts Stablecoin neobank Infini exploited for $49 million: security analysts
NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation NoOnes CEO Ray Youssef discloses $8 million exploit weeks after the fact, confirming crypto sleuth ZachXBT's investigation
Phantom Wallet raises $150 million at $3 billion valuation Phantom Wallet raises $150 million at $3 billion valuation
Crypto wallet Phantom confirms it won’t launch a token amid airdrop rumors Crypto wallet Phantom confirms it won’t launch a token amid airdrop rumors
Latest News More More
1 Day Ago Eliza Labs unveils auto.fun, a no-code AI agent launchpad with 'fairer than fair' token model
1 Day Ago Non-KYC exchange eXch to close down under money laundering scrutiny tied to Lazarus Group
2 Days Ago Base scrutinized over promotion of token that briefly crashed 95%; says part of 'contentcoin' vision
4 Days Ago Layer 1 MANTRA's token falls 90% in sudden crash; team blames 'reckless liquidations'
4 Days Ago Canada to launch spot Solana ETFs this week: report
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open