Currencies28645
Market Cap$ 2.38T-1.43%
24h Spot Volume$ 40.29B-0.52%
BTC Dominance50.77%-0.51%
ETH Gas4 Gwei
Cryptorank
CryptoRankNewsLedger Annou...

Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details


Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details
Dec, 21, 2023
2 min read
by CryptoPotato
Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details

Ledger, a hardware wallet manufacturer, has announced plans to disable blind signing for Ethereum Virtual Machine (EVM) decentralized applications (DApps) by June 2024.

The decision comes in response to an exploit where a wallet drainer was added to a library utilized by numerous DApps to connect to Ledger devices.

Ledger Announces Plan to Compensate Victims

In a tweet, Ledger revealed that approximately $600,000 in crypto assets were stolen during the recent exploit. In response to the security breach, the company announced its commitment to compensating affected victims.

It declared that it would discontinue the practice of Blind signing with Ledger devices by June 2024.

Blind signing involves displaying raw smart contract signing data, readable by computers but not by humans. The company’s decision to phase out blind signing is a step toward establishing a new standard to enhance user protection and promote clear signing across decentralized applications.

Ledger urged DApp developers to support clear signing and emphasized its dedication to preventing such incidents in the future, ensuring the ecosystem’s security.

According to Ledger, the stolen assets were taken from users blind signing on EVM DApps.

Ledger Exploit Drains Fund

In the recent exploit last week, developers on Twitter identified a malicious version of the Ledger Connect Kit, a library facilitating the connection between Ledger devices and DApps.

According to Web3 security firm BlockAid, the attacker injected a wallet-draining payload into the Ledger Connect Kit’s NPM package, allowing them to drain funds from users who signed on DApps like Sushi.com and Hey.xyz.

MetaMask, a software wallet developer, cautioned users to “stop using DApps” following news of the attack. In a subsequent statement, Ledger confirmed that the attack occurred due to a former employee falling victim to a phishing attack.

The attacker accessed the former employee’s NPMJS account, allowing them to push a malicious version of the Ledger Connect Kit. This compromised Connect Kit rerouted user funds from any wallet connecting to a DApp using it to the hacker’s wallet.

Ledger responded swiftly, deploying a fix within 40 minutes of its security teams alerting it. Meanwhile, a new version of the Connect Kit (1.1.8) has been released. The exploit did not compromise Ledger devices and the Ledger Live app.

It’s worth noting that Ledger has faced criticism over its security. In 2020, a Ledger customer email database was hacked, exposing over a million user emails. Earlier this year, Ledger’s voluntary ID-based Recover service also received criticism from users, with some calling it a “backdoor.”

The post Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details appeared first on CryptoPotato.

Read the article at CryptoPotato

Read More

U.S. Financial Industry to Explore Sharing Ledger Technology for Multiasset Transactions

U.S. Financial Industry to Explore Sharing Ledger Technology for Multiasset Transactions

Major stakeholders in the U.S. financial sector, including Citi, JPMorgan, Mastercard...
May, 08, 2024
by CoinDesk
Crypto phishing attacks plummet in April, reaching a yearly low of $38 million

Crypto phishing attacks plummet in April, reaching a yearly low of $38 million

Phishing attacks within the crypto industry decreased 46% to $38 million in April, th...
May, 06, 2024
1 min read
by CryptoSlate
CryptoRankNewsLedger Annou...

Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details


Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details
Dec, 21, 2023
2 min read
by CryptoPotato
Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details

Ledger, a hardware wallet manufacturer, has announced plans to disable blind signing for Ethereum Virtual Machine (EVM) decentralized applications (DApps) by June 2024.

The decision comes in response to an exploit where a wallet drainer was added to a library utilized by numerous DApps to connect to Ledger devices.

Ledger Announces Plan to Compensate Victims

In a tweet, Ledger revealed that approximately $600,000 in crypto assets were stolen during the recent exploit. In response to the security breach, the company announced its commitment to compensating affected victims.

It declared that it would discontinue the practice of Blind signing with Ledger devices by June 2024.

Blind signing involves displaying raw smart contract signing data, readable by computers but not by humans. The company’s decision to phase out blind signing is a step toward establishing a new standard to enhance user protection and promote clear signing across decentralized applications.

Ledger urged DApp developers to support clear signing and emphasized its dedication to preventing such incidents in the future, ensuring the ecosystem’s security.

According to Ledger, the stolen assets were taken from users blind signing on EVM DApps.

Ledger Exploit Drains Fund

In the recent exploit last week, developers on Twitter identified a malicious version of the Ledger Connect Kit, a library facilitating the connection between Ledger devices and DApps.

According to Web3 security firm BlockAid, the attacker injected a wallet-draining payload into the Ledger Connect Kit’s NPM package, allowing them to drain funds from users who signed on DApps like Sushi.com and Hey.xyz.

MetaMask, a software wallet developer, cautioned users to “stop using DApps” following news of the attack. In a subsequent statement, Ledger confirmed that the attack occurred due to a former employee falling victim to a phishing attack.

The attacker accessed the former employee’s NPMJS account, allowing them to push a malicious version of the Ledger Connect Kit. This compromised Connect Kit rerouted user funds from any wallet connecting to a DApp using it to the hacker’s wallet.

Ledger responded swiftly, deploying a fix within 40 minutes of its security teams alerting it. Meanwhile, a new version of the Connect Kit (1.1.8) has been released. The exploit did not compromise Ledger devices and the Ledger Live app.

It’s worth noting that Ledger has faced criticism over its security. In 2020, a Ledger customer email database was hacked, exposing over a million user emails. Earlier this year, Ledger’s voluntary ID-based Recover service also received criticism from users, with some calling it a “backdoor.”

The post Ledger Announces Plans to Fix Issues Related to Recent Vulnerabilities: Details appeared first on CryptoPotato.

Read the article at CryptoPotato

Read More

U.S. Financial Industry to Explore Sharing Ledger Technology for Multiasset Transactions

U.S. Financial Industry to Explore Sharing Ledger Technology for Multiasset Transactions

Major stakeholders in the U.S. financial sector, including Citi, JPMorgan, Mastercard...
May, 08, 2024
by CoinDesk
Crypto phishing attacks plummet in April, reaching a yearly low of $38 million

Crypto phishing attacks plummet in April, reaching a yearly low of $38 million

Phishing attacks within the crypto industry decreased 46% to $38 million in April, th...
May, 06, 2024
1 min read
by CryptoSlate