Hardware wallet manufacturer Ledger suffered a security incident on December 14, 2023, when its Connect Kit library was injected with malicious code, resulting in the theft of approximately $484,000 in user funds. On-chain intelligence firm Lookonchain first reported the figure, while Ledger later confirmed the details and released a patched version 1.1.8.
Incident Details: Former Employee Account Phished
According to Ledger, the attacker gained access to a former employee's NPMJS account through a phishing attack and used it to upload a compromised version of the Ledger Connect Kit (versions 1.1.5 through 1.1.7). The malicious code hijacked the legitimate WalletConnect project flow, redirecting funds to a hacker-controlled wallet. Ledger deployed a fix within 40 minutes of detection, but the malicious file remained active for approximately five hours. The actual window for fund siphoning was under two hours.
Response and Remediation
Ledger stated it collaborated with WalletConnect to disable the rogue project and automatically pushed the verified Connect Kit version 1.1.8 to users. Additionally, developer teams using the Ledger Connect Kit on NPM have been restricted to read-only access to prevent direct package updates. Ledger also noted that stablecoin issuer Tether has frozen the attacker's address, which is now traceable via Chainalysis software. At the time of writing, the wallet still holds approximately $254,000.
User Impact and Recommendations
Ledger advised users to wait 24 hours before resuming use of the Connect Kit and emphasized the importance of using Clear Signing, as well as configuring an additional Ledger wallet or manually parsing transactions for blind signing. The company is actively engaging with affected customers and working with law enforcement to track down the attacker. Furthermore, Ledger is analyzing the exploit to prevent future attacks.
This incident once again highlights the risks of supply chain attacks in the crypto ecosystem, as even hardware wallet manufacturers are not immune to vulnerabilities in third-party libraries. Users should always verify transaction details and stay updated on official security advisories.

