Plato Data Intelligence.
Vertical Search & Ai.

The Crypto Roundup: 15 December 2023 | CryptoCompare.com

Date:

Hackers have stolen over $480,000 in digital assets after they managed to infiltrate the Github library of Connect Kit, a key blockchain tool from crypto wallet firm Ledger.

Connect Kit facilitates the connection between decentralized finance (DeFi) protocols and hardware wallets, meaning the breach saw widespread impact across major DeFi protocols, prompting urgent advisories against using decentralized apps (dApps) until an update rolled out.

Protocols including Sushi, Lido, and MetaMask are all protocols that use Connect Kit and whose front-ends were affected by the security breach. Addressing the incident, Ledger confirmed an employee had been targeted in a “phishing attack” which led the attacker to publish “a malicious version of the Ledger Connect Kit.”

While Ledger has updated the code, according to security researchers full risk mitigation requires each protocol using Connect Kit to manually update their library. Currently, services used for withdrawing permissions from DeFi protocols are particularly at risk.

This incident is part of a larger trend of DeFi-related security breaches, with a staggering $303 million stolen in July alone. After these incidents, users often resort to withdrawing services to remove permissions from impacted protocols, but in this case, entire website front-ends were affected which could broaden the impact of the incident.

spot_img

Latest Intelligence

spot_img

Chat with us

Hi there! How can I help you?