Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home»Hot Topics»News»The Ledger Library exploit
    ledger war schnell beim fix des library exploit

    The Ledger Library exploit

    By Editorial Office CVJ.CH on 15. December 2023 News

    The exploit that occurred yesterday in the Ledger Library, which is integrated into many crypto projects, has caused widespread concern and market instability. This event highlights the pervasive risks in the digital asset landscape, particularly in the emerging field of decentralised finance (DeFi).

    At the heart of the crisis is a critical vulnerability in the LedgerHQ library. This software component is used by various decentralised applications (Dapps). The vulnerability allowed malicious code to be injected into the front-end of many Dapps, putting users and their assets at significant risk.

    Ledger library as means to an end

    The type of vulnerability exploited is often referred to as a "supply chain attack". In this type of attack, the target is not the end product, but one of the components. Such attacks are particularly insidious because they can simultaneously target multiple systems that use the same compromised component. In this case, the Ledger library acted as a channel, rapidly spreading the malicious code across multiple platforms. This widespread impact highlights the interconnected nature of modern crypto platforms and the cascading effects that can result from a single point of failure.

    ledger asks to use connect-kit loader to load connect-kit, but even if you follow the best practices and pin the version of the loader loader, it fetches the latest version of connect-kit >=1.0.0, <2.0.0.

    this has allowed the attackers to infiltrate a shitton of libraries by…

    — banteg (@bantg) December 14, 2023

    Ledger's response and aftermath

    In response to this crisis, Ledger, the maker of the popular hardware wallet and creator of the compromised library, acted quickly. They identified and removed the malicious version of their software and released an update to fix the vulnerability. However, the attackers were able to withdraw approximately $600,000 from wallets in the few hours of the vulnerability.

    Ledger's rapid response was exemplary in preventing further losses and restoring confidence in their systems. They urged users via X, formerly Twitter, to refrain from interacting with decentralised applications until the issue was fully resolved. However, there is no mention of the incident on Ledger's status page, official blog or developer portal.

    🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨

    A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.

    Your Ledger device and…

    — Ledger (@Ledger) December 14, 2023

    Dapp users should note that the library update does not only affect Ledger users, but must first be implemented by all projects. The risk to users is by no means eliminated. This incident serves as a reminder of the importance of strict security protocols and rapid crisis response mechanisms in the crypto industry.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    Editorial Office CVJ.CH

      The CVJ editorial staff consists of a team of Blockchain experts and informs daily and independently about the most exciting news.

      Related Articles

      CVJ.CH Weekly review calendar week

      Weekly review calendar week 19 – 2026

      JPMorgan sees Bitcoin ahead of gold in the debasement trade: GLD loses 2.7% AUM, IBIT gains 1.5% AUM since Iran war outbreak.

      JPMorgan: Bitcoin overtakes gold in the debasement trade

      The Canton of Lucerne joins the Swiss Blockchain Federation as its seventh member canton, with 73 active blockchain companies.

      Canton of Lucerne joins Swiss Blockchain Federation

      CVJ.CH Weekly review calendar week
      9. May 2026

      Weekly review calendar week 19 – 2026

      JPMorgan sees Bitcoin ahead of gold in the debasement trade: GLD loses 2.7% AUM, IBIT gains 1.5% AUM since Iran war outbreak.
      8. May 2026

      JPMorgan: Bitcoin overtakes gold in the debasement trade

      Bitcoin regime shift in question as April rally pushes BTC above $80k, with $2.4 billion in ETF inflows and patient capital building support.
      8. May 2026

      Spring cleaning: Bitcoin tests the regime shift above $80k

      twitter image button instagram image button linkedin image button youtube image button

      About Crypto Valley Journal
      About Crypto Valley Journal

      On the pulse of the movement

      • Academy
      • Contact
      • Advertising
      • About us
      • Partner
      • Imprint
      • Privacy
      • Disclaimer
      Search

      Type above and press Enter to search. Press Esc to cancel.