Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Ledger to remove Blind Sign after Connect Kit exploit, promises to return funds

Ledger to remove Blind Sign after Connect Kit exploit, promises to return funds

The Block2023/12/20 15:02
By: The Block
XOLDTOKEN0.00%
Quick Take Crypto hardware wallet manufacturer Ledger will make changes to its signing processes after a $600,000 exploit last week. Ledger also promised that affected users will be made whole by the end of February 2024.
Ledger to remove Blind Sign after Connect Kit exploit, promises to return funds image 0

Crypto hardware wallet provider Ledger will enact changes to transaction signing processes after a Dec. 14 exploit in the Ledger Connect Kit software library.

"We are aware of approximately $600,000 in assets impacted, stolen from users blind signing on EVM DApps," Ledger wrote in a Wednesday X post. It's "committing to work with the DApp ecosystem to allow Clear Signing, and no longer allow Blind Signing with Ledger devices by June 2024."

Both Ledger and non-Ledger customers who lost funds from the exploit will be "made whole" by the end of February 2024, the firm said, adding that those who signed a transaction on affected DApps should revoke unauthorized transactions to prevent the malicious code from affecting them further. 

"Our commitment is to work with the community and DApp ecosystem to allow Clear Signing so users can verify all transactions on Ledger devices before signing. This will lead to a new standard to protect users and encourage Clear Signing across DApps," Ledger wrote.

Ledger ConnectKit security issue

Last week, a critical vulnerability affecting several decentralized applications impacted a software library that Ledger relied on, The Block previously reported. Potentially due to a compromise in the software library's specific content delivery network, malicious code had been injected into the front-ends of the apps that allowed the exploiter to steal assets. 

Ledger removed the malicious code after identifying it, but third-party organizations estimated that around $500,000 in funds had been affected around the time. 


Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitget Incentive Program: Win up to 1,100 USDT Per Week
Bitget Announcement2025/10/25 16:00
CandyBomb x MET: Trade futures to share 20,000 MET!
Bitget Announcement2025/10/24 09:00
CandyBomb x MET: Trade futures to share 20,000 MET!
Bitget Announcement2025/10/24 09:00
CandyBomb x APR: Trade futures to share 88,888 APR!
Bitget Announcement2025/10/24 09:00

Trending news

More
1
Bitget Incentive Program: Win up to 1,100 USDT Per Week
2
CandyBomb x MET: Trade futures to share 20,000 MET!

Crypto prices

More
Bitcoin
Bitcoin
BTC
$111,391.17
+0.80%
Ethereum
Ethereum
ETH
$3,937.34
+0.97%
Tether USDt
Tether USDt
USDT
$1
-0.02%
XRP
XRP
XRP
$2.59
+4.27%
BNB
BNB
BNB
$1,113.71
+0.76%
Solana
Solana
SOL
$192.2
+0.46%
USDC
USDC
USDC
$0.9999
-0.03%
Dogecoin
Dogecoin
DOGE
$0.1970
+0.71%
TRON
TRON
TRX
$0.2976
-2.14%
Cardano
Cardano
ADA
$0.6551
+0.90%
How to buy BTC
Bitget lists BTC – Buy or sell BTC quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter