Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Ledger Connect Kit Supply-Chain Attack Drained More Than $600,000 From Crypto Wallets

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On December 14, 2023, attackers compromised Ledger Connect Kit, a JavaScript library used by third-party decentralized apps (dApps), and used it to trick some users into signing transactions that transferred their crypto. Contemporary reporting put losses at more than $600,000. Ledger said its hardware wallets and Ledger Live were not compromised: this was an attack on the software-distribution path and the dApp interfaces that requested users’ signatures.

The incident in brief

  • What was compromised: Ledger Connect Kit, a library that third-party websites and dApps use to connect to Ledger devices.
  • Malicious releases: @ledgerhq/connect-kit versions 1.1.5, 1.1.6 and 1.1.7.
  • How funds were taken: Malicious code altered the transaction requests shown through affected dApps. Users who signed harmful requests authorized transfers or other actions that moved assets to attacker-controlled addresses.
  • Estimated losses: More than $600,000, according to contemporaneous blockchain analysis and reporting—not a final audited total. TechCrunch reported the estimate; The Register cited approximately $650,000.
  • Exposure period: Ledger said malicious files were available for about five hours, but estimated active draining lasted less than two hours.

Ledger’s incident report and CEO statement are the primary sources for the technical account and response.

What was—and was not—compromised

Ledger Connect Kit is software for connecting a Ledger signer to third-party dApps; it is not the Ledger hardware wallet itself. The attacker used access to a former employee’s NPM account to publish malicious package versions. NPM is a registry developers use to distribute JavaScript packages. A loader and CDN arrangement meant some dApps could fetch Connect Kit code dynamically, so a poisoned package could reach sites that had not independently published a new release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ledger said the attacker did not access Ledger hardware, Ledger Live, its internal code repository or the affected dApps themselves. The precise description is therefore: a Ledger-published wallet-connection library’s distribution path was compromised, exposing users of some third-party dApp front ends. Calling it a direct hardware-wallet or private-key theft misstates the reported attack.

#1 Best Overall
Ledger Nano X - Classic Crypto Wallet with Bluetooth
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
  • Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
  • Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.

How the attack worked

The sequence was essentially:

Phishing and credential/session abuse → former employee’s NPM access → malicious Connect Kit releases → dApp loads altered code → user connects wallet → user signs a malicious request → assets move

Ledger attributed initial access to phishing of a former employee. The employee’s internal Ledger access had been revoked, but NPM access had not been manually removed. Ledger’s root-cause account says the attacker abused an associated API or session credential to bypass the account’s two-factor protection. The failure was not simply that a device was “hacked”: it involved credential abuse and incomplete offboarding from an external publishing service.

The injected code used a fraudulent WalletConnect project and an Angel Drainer payload. It could present fake claims, token transfers or other transaction requests. A user who signed such a request gave the blockchain a valid authorization to carry it out.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Ledger Nano S Plus - Classic Crypto Wallet
  • All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
  • Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
  • Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
  • Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.

Why the Ledger device did not prevent the loss

A hardware wallet keeps the private key on the device and uses it to sign transactions. It does not independently know whether a dApp’s request is honest, nor can it make every signed transaction safe. If a compromised interface asks for a harmful transfer or approval and a user authorizes it, the device can protect the key while still signing the transaction that loses funds.

This is the distinction between key security and transaction safety. A valid hardware-backed signature proves that the key authorized a request; it does not prove that the request was legitimate or financially wise. A user can lose assets this way without ever entering a recovery phrase.

Clear signing presents meaningful transaction details on the device for review. Blind signing means the device shows limited or opaque information, leaving the user to trust the dApp or interpret data they may not understand. Ledger urged users to use clear signing. It can make unexpected details easier to spot, but it is not immunity: visibility varies by device, app, chain and transaction type, and the user still has to check what is displayed.

Rank #3
Ledger Flex Crypto Wallet Securely Manage All Your Digital Assets
  • Simply & securely take control of your digital assets and identity with the all-in-one Ledger Wallet crypto app and Ledger Flex touchscreen signer.
  • Digital asset control at your fingertips: manage 15,000+ crypto across multiple chains. Earn rewards. Top up & share with ease. Explore DeFi with confidence. Collect and showcase NFTs. Make informed choices with clarity.
  • Connect effortlessly with Ledger Wallet: pair your secure Ledger signer with the all in one Ledger Wallet crypto app to manage thousands of digital assets across multiple devices and accounts with Ledger Sync from a single, secure dashboard.
  • Cutting-edge design: monitor the market, compare rates, and Clear Sign transactions on the secure, high resolution, 2.8'' E Ink touchscreen.
  • This is what security feels like: Ledger touchscreen signers all come with a private, offline, PIN-protected backup, Ledger Recovery Key, to never lose access to your assets.

Timeline (CET, December 14, 2023)

  • 09:49, 10:44 and 11:37: The malicious Connect Kit versions were published.
  • 13:45: Ledger was alerted by ecosystem participants, including Blockaid.
  • 14:18: Ledger’s technical and security teams were alerted. Ledger said it deployed a genuine fix within 40 minutes of becoming aware.
  • 14:55: Tether froze USDT associated with the attacker after coordination.
  • About five hours: Malicious files remained available, in part because of CDN and cache propagation. Ledger estimated active draining at less than two hours.
  • December 20: Ledger published its formal incident report.

Ledger identified version 1.1.8 as the clean replacement at the time. That is a historical remediation detail, not a recommendation to use that version today; developers should follow Ledger’s current developer documentation and verify present package guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who was at risk?

Exposure depended on the dApp’s integration and what the user did. The relevant risk was for people who used an affected third-party dApp while it loaded a malicious version and then signed a harmful request. Not every dApp integration necessarily served the malicious code, and not every visitor signed a transaction.

  • Held crypto on a Ledger but did not use an affected dApp: Ledger did not describe simply holding funds as exposure to this incident.
  • Used Ledger Live only: Ledger said Ledger Live was not affected.
  • Connected to a dApp but signed nothing: The reported theft mechanism required users to authorize harmful transactions; merely owning a device or connecting is not the same as signing one.
  • Signed a transaction through an affected dApp during the window: Review the relevant chain activity and approvals. The actual risk depends on the transaction signed.

These distinctions reflect Ledger’s account; they are not a universal guarantee about every third-party integration or every user’s activity.

Rank #4
Ledger Nano Gen5 - Crypto Wallet - Securely Buy Digital Assets - Black
  • More than just crypto: confirm your device is authentic with Genuine Check, manage all your logins with Ledger Security Key, detect common scams with Transaction Check and more.
  • Industry-defining security: battle-tested by the Donjon's white hat hackers, protected by the Secure Element, and powered by Ledger OS.
  • Connect effortlessly with Ledger Wallet: pair your secure Ledger signer with the all in one Ledger Wallet crypto app to manage thousands of digital assets across multiple devices and accounts with Ledger Sync from a single, secure dashboard.
  • Playful, user-friendly design: monitor the market, compare rates and Clear Sign all transactions on the secure 2.8'' anti-glare, scratch-resistant touchscreen.
  • This is what security feels like: Ledger touchscreen signers all come with a private, offline, PIN-protected backup, Ledger Recovery Key, to never lose access to your assets.

If you think you interacted with an affected dApp

  1. Stop using the dApp until you verify its current status. Use a trusted, official channel—not a link in a direct message or search ad.
  2. Review activity on the relevant chains around December 14, 2023, including transfers, token approvals and contract interactions. Compare transaction details with your own records.
  3. Consider revoking remaining token approvals with a reputable approval-management tool. Verify the site and inspect the revocation transaction before signing. Revocation may limit future use of an allowance; it cannot reverse assets already transferred, and revoking may itself require an on-chain transaction.
  4. If you believe an unsafe permission remains, consider moving remaining assets to a fresh account generated securely. Verify the new address carefully and do not reuse a possibly exposed recovery phrase.
  5. Keep evidence: save transaction hashes, timestamps, dApp URLs, screenshots and wallet addresses before contacting the dApp, an exchange or law enforcement.
  6. Contact Ledger only through its official support channel. Never give anyone your recovery phrase, PIN or private key.

Do not expect a firmware update or PIN change to recover assets already transferred. The reported theft involved transactions users signed, not the extraction of a Ledger seed phrase. Be wary of unsolicited recovery offers, especially anyone demanding an upfront fee or asking for wallet credentials.

Ledger said it reported the attacker’s address, coordinated with Chainalysis and WalletConnect, helped Tether freeze associated USDT and would assist affected users and work with law enforcement. Its statement does not establish that all stolen assets were recovered or all victims reimbursed. The attacker address Ledger published was 0x658729879fca881d9526480b82ae00efc54b5c2d.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What dApp developers should take from it

The central supply-chain lesson is that a dApp can inherit risk from code it does not host or release itself. A dynamically loaded library can be convenient, but it can also let a compromised upstream package reach many otherwise separate front ends. Pinning versions reduces surprise updates; it does not by itself guarantee that a selected version is safe.

Best Value
Ledger Nano S Plus - Classic Crypto Wallet
  • All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
  • Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
  • Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Choose the colors that match your style: express your personality and your crypto management mood, color code your signers, one for each use (trading, staking, HOLDing...).
  • Control dependency changes: Pin critical packages to reviewed versions, maintain a software bill of materials, and monitor releases, maintainer changes and package provenance.
  • Protect publishing: Require multi-person approval for releases, use short-lived credentials and hardware-backed authentication where possible, and revoke external registry access during employee offboarding.
  • Constrain delivery: Avoid dynamically loading security-sensitive code from mutable, uncontrolled CDNs. Consider self-hosting reviewed assets and using subresource integrity where applicable to check fetched scripts against expected hashes.
  • Limit browser reach: Use a restrictive Content Security Policy to reduce where scripts and injected code can connect. CSP and integrity controls are mitigations, not substitutes for a secure release process.
  • Test the transaction boundary: Add checks for unexpected recipients, approval scopes and contract calls; ensure users receive meaningful transaction details before signing.
  • Prepare for containment: Monitor anomalous publications, test how cached and geographically distributed copies behave, and plan how to disable or isolate a compromised integration quickly.

These are general defensive practices, not a claim that Ledger had or lacked each control in 2023. Ledger said it would make the Connect Kit team read-only on NPM, rotate publishing secrets, publish through a GitHub-controlled process, strengthen supply-chain controls and improve external-service offboarding. Those are Ledger’s stated remediation steps; the public postmortem alone does not independently verify every control’s later implementation.

Why the incident still matters

The attack illustrates a broader Web3 security boundary: a hardware wallet may safeguard private keys while the web interface that constructs a transaction is compromised. Package registries, CDNs, dependency credentials and dApp interfaces can become part of the path between a user and a signature. Security therefore depends not only on where keys are stored, but also on what the user is asked to authorize and how clearly that request is presented.

Changing hardware-wallet brands would not, by itself, prevent a deceptive dApp request, malicious approval or compromised dependency. A separate lower-value account for dApp activity can limit potential exposure, but it adds key-management complexity and still requires transaction review. The practical defenses are careful signing, limited approvals, trustworthy software delivery and skepticism toward unexpected prompts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Loss figures and the incident timeline above are based on contemporary reporting and Ledger’s 2023 disclosures. The supplied evidence does not establish a final accounting of losses, complete recovery or compensation for every victim.

Quick Recap

Bestseller No. 1
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.; Product color may vary slightly from pictures due to manufacturing process.
$99.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.