Skip to content

Home  About  Disclaimer  Privacy  Editorial  Advertise

Menu
  • Home
  • Artificial Intelligence Trading
  • Prop
  • Brokers
  • Exchanges
  • Blockchain
  • Guides
  • Sitemap
  • Contact
Menu

Single Phishing Link Unleashes Havoc in the Crypto Industry

Posted on December 15, 2023

In its Thursday evening statement, Ledger revealed how the attack unfolded when its former staff suffered a phishing attack.

The crypto wallet developer Ledger admitted the exploit in a warning to the community to halt using decentralized applications (dapps).

Ledger disclosed that the attack arose from a phishing scam that targeted a former staff member. 

AI Trading

Ledger iterated that the compromised code captured the ex-staff’s identity and email address. The firm rubbished initial claims by the crypto community, alleging the developer was behind the exploit. 

The orchestrator accessed the ex-employee’s NPMJS account involving a package manager in JavaScript programming language. Packages involve libraries developers utilize in building projects instead of coding from scratch. The developers in the Web3 community apply packages to build interoperable decentralized apps from various wallets. 

Ledger Admits Compromise in Connect Kit Version

The statement indicated that the exploiter leveraged the access to the NPMJS to launch a malicious Ledger Connect Kit version. The push rendered all projects utilizing the Connect Kit vulnerable to the malicious code that ultimately rerouted users’ funds to the hacker’s wallet. 

Ledger clarified that the Connect Kit affected included 1.1.5, 1.1.6, and 1.1.7 versions. The firm confirmed striking out the versions from the NPM page. 

The company confirmed that its technology and security units were alert to potential attacks. The teams quickly fixed it within 40 minutes of discovering the vulnerability. 

Ledger’s statement revealed that the malicious file ran live for closer to 5 hours. Nonetheless, Ledger indicated that the window of draining the wallets hardly exceeded two hours. 

AI Trading

Ledger confirmed pushing a new Connect Kit version 1.1.8 with units utilizing it, realizing automatic updates. The company warned the users to observe the 24 hours before connecting to the decentralized application. 

Field chief technical executive at cyber security specialist Sonatype Illka Turunen indicated that the huge number of repositories hosted upon GitHub relying upon the connect-kit loader suggests widespread destruction suffered by the crypto supply chain. 

Turunen indicated that unless the developers execute intensive hygiene before its reconsumption. 

The exploit triggered widespread panic across the crypto ecosystem. Aftab Hossain, popularly identified as DCInvestor on X, termed it absurd and unacceptable the developer’s possibility of a single click to phishing link compromising the front-end of the meaningful application.

Angel Drainer Involvement in Ledger Exploit

Global leading stablecoin issuer Tether confirmed freezing the funds allegedly connected to the wallet utilized by the exploiter who drained the $484,000 from the decentralized finance (DeFi) users. Tether chief executive Paolo Ardoino disclosed that the wallet held a USDT balance worth $27000 from $334,814. 

Further analysis indicated that the wallet contained $484,000 at one point. The on-chain data reveals the wallet’s involvement in transferring funds to the wallet connected to the Angel Drainer.

The phishing group involved in the Ledger exploit linked it with other criminal acts involving DeFi hacks. The stolen assets feature a Doodle NFT exchanging hands at 3.9 ETH, though labeled for suspicious activity on the OpenSea marketplace. 

Drainers execute their criminal activities by convincing users to approve transactions secretly, giving them access to funds in their wallets. The drainers are utilizing creative names rented to the hackers for a cut of the illicit proceeds.  

Editorial credit: Anton Gvozdikov / Shutterstock.com


SureTradeGroup.com is not responsible for the content, accuracy, quality, advertising, products or any other content posted on the site. Some of the content on this site is paid content that is not written or posted by our writers or editors and the opinions expressed do not reflect the opinions of this website. Any disagreement you may have with brands or companies mentioned in articles will need to be taken care of directly with those specific brands and companies. The responsibility of anyone who may click links in our articles and ultimately sign up for that product or service is their own. Forex, Stocks, Cryptocurrencies, NFTs and Dogital Tokens are all a high-risk asset, investing in them can lead to losses. Readers should do their own research before taking any action.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Try The #1 Artificial Intelligence Trading System For Free

Looking for something?

Crypto Prices

Name Price24H (%)
bitcoin
Bitcoin (BTC)
$71,159.00
2.06%
ethereum
Ethereum (ETH)
$3,680.97
7.46%
tether
Tether (USDT)
$1.00
0.03%
binancecoin
BNB (BNB)
$583.95
0.09%
solana
Solana (SOL)
$177.21
0.26%
ripple
XRP (XRP)
$0.62
4.26%
usd-coin
USDC (USDC)
$1.00
0.02%
dogecoin
Dogecoin (DOGE)
$0.199372
-0.67%
cardano
Cardano (ADA)
$0.61
4.67%
binance-usd
BUSD (BUSD)
$1.00
-0.44%

Recent Posts

  • Full IGW Management Review – (4.5 out of 5): A Step-by-Step Evaluation of IGW Management
  • Full Nova Trade Review – (4.5 out of 5): A Step-by-Step Evaluation of Nova Trade
  • World Wide Chain Review – Is World Wide Chain Scam or Legit?
  • Full CW Management Review (4.5 out of 5): A Step-by-Step Evaluation of CW Management
  • Full Wealth Fronts Review (4.5 out of 5): A Step-by-Step Evaluation of Wealth Fronts
  • Full Aurum Group Review – (4.5 out of 5): A Step-by-Step Evaluation of Aurum Group
  • Full WS Group Review (4.5 out of 5): A Step-by-Step Evaluation of WS Group
  • Full EmberPrime.com Review (4.5 out of 5) A Step-by-Step Evaluation of Ember Prime (EmberPrime)
  • Full CanaBit.AI Review (4.5 out of 5) A Step-by-Step Evaluation of CanaBit AI (CanaBitAI)
  • US Treasury Allegedly Pressured Fed to Halt Facebook Libra Stablecoin
  • Bitcoin Surges Toward $100K as South Korea Cuts Interest Rates Again
  • Bitcoin Nears $100K: Trezor Wallet Sales Skyrocket 600% Amid Rally
  • Uniswap’s $15.5M Bounty Fuels UNI’s 30% Surge to $11.50
  • Spines Faces Pushback From Authors on AI-Powered Book Publishing Plans
  • Ripple CEO Brad Garlinghouse Rumored as Trump’s Pick for Crypto Czar Role
  • Dogecoin Drops 4% as Market Cools: Is the Meme Coin Rally Over?

Invest in Crypto

  • Binance
  • Capital.com
  • Eightcap
  • Invast Global
  • Kraken
  • Synergy FX
  • Coincheck
  • Gemini
  • FTX
  • Coinbase
  • Gate.io
  • KuCoin
  • Bitfinex
  • Huobi Global
  • Bybit
  • Bitstamp
  • OKX
  • MEXC
  • Phemex
  • Bithumb
  • LBank
  • Upbit
  • Bittrex
  • OFP Funding
©2025 Sure Trade Group | Design: Newspaperly WordPress Theme