Ledger Connect Kit Breach: Hacker Drains $484K, Firm Rolls Out Emergency Fix

Ledger Connect Kit Breach: Hacker Drains $484K, Firm Rolls Out Emergency Fix

N
News Editor 01
2026-07-08 17:20:14
A former employee's compromised NPMJS account led to a malicious update of Ledger's Connect Kit, siphoning ~$484K from wallets. Ledger patched within 40 minutes and released v1.1.8. Tether froze the hacker's address.
LedgerConnect Kitsecurity breachhackcryptocurrency

The hardware wallet manufacturer Ledger has suffered a significant security incident as its Connect Kit library was exploited, resulting in the theft of approximately $484,000 from user wallets. Onchain intelligence firm Lookonchain first reported the loss, while Ledger confirmed the attack originated from a phishing breach of a former employee's NPMJS account.

Breach Details: Former Employee Account as Entry Point

According to Ledger's official statement, the attacker used a phishing attack to gain access to a former employee's NPMJS account and uploaded malicious versions of the Connect Kit library (versions 1.1.5 through 1.1.7). The malicious code masqueraded as a legitimate Walletconnect project, redirecting user funds to a hacker-controlled wallet address. Ledger's tech team deployed a fix within 40 minutes of discovering the issue, though the malicious file remained active for approximately five hours. The actual fund siphoning period was less than two hours.

Response: Emergency Version 1.1.8 Released

Ledger has automatically pushed the verified Connect Kit v1.1.8 and advised users to wait 24 hours before resuming use. To prevent similar incidents, development teams working with the Ledger Connect Kit on NPM have been restricted to read-only access, preventing direct package updates. Additionally, Tether has frozen the hacker's address (0x658729879fca881d9526480b82ae00efc54b5c2d), which currently holds approximately $254K. Ledger stated it is working with law enforcement to track down the attacker and analyzing the exploit to prevent future attacks.

Loss Investigation: Amount Not Officially Confirmed

While Lookonchain reported the stolen amount as $484,000, Ledger has not directly confirmed this figure, only disclosing the hacker's wallet address. The company emphasized it is actively engaging with affected customers and providing support. Ledger reiterated the importance of Clear Signing and suggested using an additional Ledger mint wallet or manual transaction parsing to avoid blind signing.

This incident once again highlights the supply chain security risks within the hardware wallet ecosystem. Although Ledger's hardware devices themselves were not compromised, vulnerabilities in the Connect Kit library still caused direct user losses. The community urges all DApp developers and wallet users to check if they are using affected versions and update to version 1.1.8 immediately.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.