logo

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned

ID: 7f6549bb-be55-54dd-921b-74f7922ad210

STIX ID: report--7f6549bb-be55-54dd-921b-74f7922ad210

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2023-12-16

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Ledger's Connect Kit NPM package was hijacked after a former employee fell for a phishing attack that allowed an attacker to publish malicious versions (1.1.5–1.1.7) containing a crypto-drainer. The malicious release was live for a short window (active ~2 hours), during which attackers stole roughly $610k–$850k from victims; Ledger patched and published a safe version (1.1.8), identified the attacker's address, and reported token freezes and notifications to authorities. The incident exposes weak distribution practices (CDN unpinned delivery), missing NPM two-factor authentication and access revocation gaps, increasing supply-chain risk for projects that automatically fetched the latest Connect Kit release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.