Ledger, the leading hardware wallet manufacturer, has disclosed a security breach involving its Connect Kit library, which allowed a hacker to exploit malicious code and steal approximately $484,000 from user wallets. The onchain intelligence firm Lookonchain first reported the stolen funds, while Ledger confirmed the attack originated from a phishing attack targeting a former employee's NPMJS account.
Attack Details: Former Employee Account Compromised
According to Ledger's incident report, the attacker successfully phished a former Ledger employee and gained access to their NPMJS account, which had permissions to publish updates to the Ledger Connect Kit package. The hacker then uploaded a malicious version of the library (versions 1.1.5 through 1.1.7) that injected code to redirect Walletconnect transactions to a wallet controlled by the attacker. Ledger stated that the malicious file was active for approximately five hours, but the actual window for fund drainage was less than two hours.
Emergency Response: Patch in 40 Minutes, v1.1.8 Rolling Out
Ledger's technology and security teams became aware of the issue and deployed a fix within 40 minutes. The company collaborated with Walletconnect to disable the rogue project that was rerouting transactions. Now, the verified Ledger Connect Kit version 1.1.8 is being automatically disseminated to users. Ledger advises a 24-hour waiting period before resuming use of the Connect Kit to ensure stability. Additionally, development teams working with NPMJS have been restricted to read-only access to prevent direct package updates.
Funds and Countermeasures
Lookonchain reported that $484,000 was siphoned from wallets. Ledger has not officially confirmed the amount but has publicly released the attacker's wallet address: 0x658729879fca881d9526480b82ae00efc54b5c2d. The wallet currently holds $254,000 as of writing. Stablecoin issuer Tether has frozen the address, and the wallet is now visible through Chainalysis software, enabling law enforcement tracking. Ledger is actively engaging with affected customers and working with authorities to identify the attacker.
Security Recommendations and Industry Impact
Ledger reiterated the importance of Clear Signing and suggested using an additional Ledger mint wallet or manual transaction parsing when dealing with blind signing scenarios. This incident highlights the growing risk of supply chain attacks in the cryptocurrency ecosystem, particularly for projects that depend on third-party libraries. Ledger emphasized its commitment to analyzing the exploit to prevent future attacks. The company's transparent and rapid response has been praised by some in the community, though the breach underscores the ongoing need for vigilance among all crypto users. Users are urged to update their Connect Kit to version 1.1.8 and enable additional security measures such as transaction verification and hardware wallet best practices.
The attack serves as a reminder that even established security-focused companies can fall victim to sophisticated phishing and social engineering. As the investigation continues, the broader crypto industry will likely revisit its reliance on npm packages and shared libraries, potentially accelerating the adoption of more secure development and deployment practices.

