The hardware wallet manufacturer Ledger has suffered a significant security incident as its Connect Kit library was exploited, resulting in the theft of approximately $484,000 from user wallets. Onchain intelligence firm Lookonchain first reported the loss, while Ledger confirmed the attack originated from a phishing breach of a former employee's NPMJS account.
Breach Details: Former Employee Account as Entry Point
According to Ledger's official statement, the attacker used a phishing attack to gain access to a former employee's NPMJS account and uploaded malicious versions of the Connect Kit library (versions 1.1.5 through 1.1.7). The malicious code masqueraded as a legitimate Walletconnect project, redirecting user funds to a hacker-controlled wallet address. Ledger's tech team deployed a fix within 40 minutes of discovering the issue, though the malicious file remained active for approximately five hours. The actual fund siphoning period was less than two hours.
Response: Emergency Version 1.1.8 Released
Ledger has automatically pushed the verified Connect Kit v1.1.8 and advised users to wait 24 hours before resuming use. To prevent similar incidents, development teams working with the Ledger Connect Kit on NPM have been restricted to read-only access, preventing direct package updates. Additionally, Tether has frozen the hacker's address (0x658729879fca881d9526480b82ae00efc54b5c2d), which currently holds approximately $254K. Ledger stated it is working with law enforcement to track down the attacker and analyzing the exploit to prevent future attacks.
Loss Investigation: Amount Not Officially Confirmed
While Lookonchain reported the stolen amount as $484,000, Ledger has not directly confirmed this figure, only disclosing the hacker's wallet address. The company emphasized it is actively engaging with affected customers and providing support. Ledger reiterated the importance of Clear Signing and suggested using an additional Ledger mint wallet or manual transaction parsing to avoid blind signing.
This incident once again highlights the supply chain security risks within the hardware wallet ecosystem. Although Ledger's hardware devices themselves were not compromised, vulnerabilities in the Connect Kit library still caused direct user losses. The community urges all DApp developers and wallet users to check if they are using affected versions and update to version 1.1.8 immediately.

