Security issue in Ledger ConnectKit library affects multiple decentralized applications
Quick Take A significant security vulnerability has been reported by several decentralized applications. The issue stems from a compromised software library connected to Ledger.
A critical web3 security vulnerability emerged today, reportedly affecting several decentralized applications. The issue is related to a software library from the crypto hardware wallet provider Ledger, the “LedgerHQ” library, that dapps rely on for use with the crypto wallet service. This vulnerability could potentially allow malicious code to be injected into numerous dapps on their front-ends — posing a significant risk to users and their assets.
Consequently, front ends to dapps such as SushiSwap, Kyber, RevokeCash and Zapper could be vulnerable if used. Both Kyber and RevokeCash confirmed on X that they disabled their front-ends.
According to reports, the library code was replaced with malicious software created by hackers and designed to drain assets.
Security firm Blockaid described it as a "supply chain attack" on Ledger Connect Kit and claimed that $150,000 had been lost in the past couple of hours.
The issue likely emerged due to a specific Content Delivery Network used to host the software library being affected, according to Sushi’s chief technology officer Mathew Lilly. “LedgerHQ/connect-kit loads JavaScript from a CDN. Their CDN account has been compromised, which is injecting malicious JavaScript into multiple dApps,” Lilly said.
A potentially software patch was finalized in an update and may need to be adopted by dapps before conditions are safe.
Meanwhile, Lilly and others have warned users to avoid interacting with any dapps until further notice.
Ledger did not immediately respond to a request for comment.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
New spot margin trading pair — HOLO/USDT!
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn
- FUN plunged 32.34% in 24 hours to $0.008938, marking a 541.8% monthly loss amid prolonged bearish trends. - Technical breakdowns, elevated selling pressure, and forced liquidations highlight deteriorating market sentiment and risk-off behavior. - Analysts identify key support below $0.0080 as critical, with bearish momentum confirmed by RSI (<30) and MACD indicators. - A trend-following backtest strategy proposes short positions based on technical signals to capitalize on extended downward trajectories.

OPEN has dropped by 189.51% within 24 hours during a significant market pullback
- OPEN's price plummeted 189.51% in 24 hours to $0.8907, marking its largest intraday decline in history. - The token fell 3793.63% over 7 days, matching identical monthly and yearly declines, signaling severe bearish momentum. - Technical analysts cite broken support levels and lack of bullish catalysts as key drivers of the sustained sell-off. - Absence of stabilizing volume or reversal patterns leaves the market vulnerable to further downward pressure.

New spot margin trading pair — LINEA/USDT!
Trending news
MoreCrypto prices
More








