Ledger Connect Kit Hack: $484K Stolen, Company Pushes Emergency Fix v1.1.8

Ledger Connect Kit Hack: $484K Stolen, Company Pushes Emergency Fix v1.1.8

N
News Editor 01
2026-07-08 17:26:15
Ledger's Connect Kit library was compromised via a phishing attack on a former employee's NPMJS account, resulting in approximately $484,000 in user funds being drained. The company deployed version 1.1.8 within 40 minutes and worked with Walletconnect to disable the malicious project.
security breachLedgerhackcrypto walletssupply chain attack

Ledger, the leading hardware wallet manufacturer, has disclosed a security breach involving its Connect Kit library, which allowed a hacker to exploit malicious code and steal approximately $484,000 from user wallets. The onchain intelligence firm Lookonchain first reported the stolen funds, while Ledger confirmed the attack originated from a phishing attack targeting a former employee's NPMJS account.

Attack Details: Former Employee Account Compromised

According to Ledger's incident report, the attacker successfully phished a former Ledger employee and gained access to their NPMJS account, which had permissions to publish updates to the Ledger Connect Kit package. The hacker then uploaded a malicious version of the library (versions 1.1.5 through 1.1.7) that injected code to redirect Walletconnect transactions to a wallet controlled by the attacker. Ledger stated that the malicious file was active for approximately five hours, but the actual window for fund drainage was less than two hours.

Emergency Response: Patch in 40 Minutes, v1.1.8 Rolling Out

Ledger's technology and security teams became aware of the issue and deployed a fix within 40 minutes. The company collaborated with Walletconnect to disable the rogue project that was rerouting transactions. Now, the verified Ledger Connect Kit version 1.1.8 is being automatically disseminated to users. Ledger advises a 24-hour waiting period before resuming use of the Connect Kit to ensure stability. Additionally, development teams working with NPMJS have been restricted to read-only access to prevent direct package updates.

Funds and Countermeasures

Lookonchain reported that $484,000 was siphoned from wallets. Ledger has not officially confirmed the amount but has publicly released the attacker's wallet address: 0x658729879fca881d9526480b82ae00efc54b5c2d. The wallet currently holds $254,000 as of writing. Stablecoin issuer Tether has frozen the address, and the wallet is now visible through Chainalysis software, enabling law enforcement tracking. Ledger is actively engaging with affected customers and working with authorities to identify the attacker.

Security Recommendations and Industry Impact

Ledger reiterated the importance of Clear Signing and suggested using an additional Ledger mint wallet or manual transaction parsing when dealing with blind signing scenarios. This incident highlights the growing risk of supply chain attacks in the cryptocurrency ecosystem, particularly for projects that depend on third-party libraries. Ledger emphasized its commitment to analyzing the exploit to prevent future attacks. The company's transparent and rapid response has been praised by some in the community, though the breach underscores the ongoing need for vigilance among all crypto users. Users are urged to update their Connect Kit to version 1.1.8 and enable additional security measures such as transaction verification and hardware wallet best practices.

The attack serves as a reminder that even established security-focused companies can fall victim to sophisticated phishing and social engineering. As the investigation continues, the broader crypto industry will likely revisit its reliance on npm packages and shared libraries, potentially accelerating the adoption of more secure development and deployment practices.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.