logo
  • menu
  • Markets
  • ETFs
  • Live
  • Spot
  • Futures
  • Learn
  • Sign In
  • Sign Up
  • Downloads
  • English
  • |
  • USD
  • |
Sign Up
Crypto PricesLearnLatest NewsDownloadsMarketsSpotAnnouncements
Home/
Latest News/
Industry

Ledger Resolves Vulnerability Impacting DApps and Connector Library

By Craig Green
Dec 18, 2023
4.5 
★
★
★
★
★
★
★
★
★
★
 67 User Rating
Share

On December 14, multiple decentralized applications (DApps) using the Ledger connector encountered front-end compromises, including platforms like Zapper, SushiSwap, Phantom, Balancer, and Revoke.cash. Approximately three hours after the discovery of the security flaw, Ledger reported that the malicious file version had been replaced by a legitimate version at around 1:35 PM UTC.

Ledger issued a cautionary advisory, urging users to "always clear signed" transactions. It emphasized that the information displayed on Ledger's screens should be treated as the authentic data, advising users to halt transactions if they notice any discrepancies between their Ledger device and their computer or phone screens.

SushiSwap's CTO, Matthew Lilley, was among the first to bring attention to the issue. He pointed out that a commonly used Web3 connector had been compromised, allowing the injection of malicious code into numerous DApps. Lilley attributed the ongoing vulnerabilities and compromises on multiple DApps to Ledger, alleging that Ledger's content delivery network had been breached, resulting in the loading of compromised JavaScript.

The Ledger Connector, a library maintained by Ledger and utilized by numerous DApps, underwent an adjustment to include a wallet depletion procedure, preventing users' accounts from being depleted of assets autonomously. However, this adjustment might prompt browser wallets like MetaMask to display notifications that could potentially grant access to malicious actors seeking access to the assets.

Lilley cautioned users against engaging with any DApp utilizing the Ledger connector. He emphasized that the "connect-kit" was also vulnerable, stressing that this was not an isolated attack but rather a large-scale assault on multiple DApps. Hudson Jameson, the vice president of Polygon Labs, remarked that even after Ledger rectifies the faulty code within its library, projects utilizing the library will need to update their systems before they can safely use DApps from the Ledger Web3 library.

Acknowledging the vulnerability in its code, Ledger assured that it had removed the malicious version of the Ledger Connect Kit. The company stated that legitimate versions were being pushed out to replace the compromised files. Ledger also indicated that users were not at risk unless they initiated transactions and advised against interacting with Revoke.cash due to particular susceptibility, cautioning users about the potential risk to funds. Numerous affected sites continued to be impacted, affecting users and funds worth hundreds of thousands of dollars over the past two hours.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of BitKan. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. BitKan shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. Products mentioned in this article may not be available in your region.

Related News

  • Stablecoin Secondary Market Rules Pit Banks Against Crypto

    Stablecoin Secondary Market Rules Pit Banks Against Crypto

    The Bank Policy Institute and The Clearing House want anti-money laundering rules to cover secondary market activity.
    Martha Grizzard
    Jun 12, 2026
  • TRC20-USDT Circulation Soars to 89.3 Billion Record on TRON

    TRC20-USDT Circulation Soars to 89.3 Billion Record on TRON

    The circulation of TRC20-USDT has officially ascended to a historic peak of 89.3 billion tokens, fundamentally expanding the liquidity threshold of the decentralized financial landscape.
    Hallie Gill
    May 12, 2026
  • 21Shares Debuts First Canton Network ETF (TCAN) on Nasdaq

    21Shares Debuts First Canton Network ETF (TCAN) on Nasdaq

    The TCAN ETF provides the first U.S.-listed gateway to Canton Coin (CC), the native utility token of the Canton Network.
    Martha Grizzard
    May 8, 2026

Latest News

Industry

Cryptocurrency

Airdrop

Markets

  • Japan Regulators Greenlight Ripple’s RLUSD Stablecoin Launch

    Japan Regulators Greenlight Ripple’s RLUSD Stablecoin Launch

    The Japan Financial Services Agency (JFSA) approved RLUSD under the Payment Services Act.
    Wayne Ingram
    Jun 25, 2026
  • SpaceX Prices Record $75B IPO at $135, Hits $1.8T Valuation

    SpaceX Prices Record $75B IPO at $135, Hits $1.8T Valuation

    SpaceX has officially executed the largest initial public offering in Wall Street history, substantially eclipsing all previous market records.
    Wayne Ingram
    Jun 12, 2026
  • Stablecoin Secondary Market Rules Pit Banks Against Crypto

    Stablecoin Secondary Market Rules Pit Banks Against Crypto

    The Bank Policy Institute and The Clearing House want anti-money laundering rules to cover secondary market activity.
    Martha Grizzard
    Jun 12, 2026
  • VerifiedX Launches Bitcoin Sidechain for Native DeFi Privacy

    VerifiedX Launches Bitcoin Sidechain for Native DeFi Privacy

    VerifiedX has officially introduced a decentralized "reliever chain" designed to bring programmable, privacy-preserving functionality to the Bitcoin network.
    Martha Grizzard
    May 18, 2026
  • Japan’s SBI and Rakuten Plan Crypto Trusts as Rules Finalize

    Japan’s SBI and Rakuten Plan Crypto Trusts as Rules Finalize

    SBI Securities and Rakuten Securities have officially announced plans to introduce cryptocurrency investment trusts to their massive retail user bases.
    Craig Green
    May 18, 2026
View more data 

Top

View more
  1. 1S&P 500 Reclaims 200-Day Moving Average, Bitcoin Gains
  2. 2Trump Softens His Stance on Reciprocal Tariffs, US Stocks and Crypto Markets Rise
  3. 3Vitalik Buterin : The current price of ETH has not been affected by the merger event
  4. 4Vibhu Norby : Solana Spaces store to bring 100K people to Solana per month
  5. 5CZ: compared with the record high nine months ago, the current situation of the industry is much better

Top Gainers

View more
Bondex
BondexBDXN

$0.000940

+71.01%
Atletico Madrid Fan Token
Atletico Madrid Fan TokenATM

$2.2190

+54.85%
BNB Attestation Service
BNB Attestation ServiceBAS

$0.0532

+49.77%
Synapse
SynapseSYN

$0.3695

+31.42%
FUNTOKEN
FUNTOKENFUNTOKEN

$0.002758

+29.64%

Top Trending

View more
Silver
SilverXAG

$57.4300

-6.14%
Humanity
HumanityH

$0.0526

-46.13%
Bitcoin Cash
Bitcoin CashBCH

$195.900

+1.03%
AAVE
AAVEAAVE

$82.6900

+15.22%
Ethena
EthenaENA

$0.0854

+1.18%

Recently added

View more
Nesa
NesaNES

$0.2453

+6.65%
Arcium
ArciumARX

$0.2519

-17.22%
Ambire AdEx
Ambire AdExADX

$0.0577

+3.96%
Re
ReRE

$0.5847

-20.11%
o1 exchange
o1 exchangeO

$0.6017

+10.48%

Learn

View more
  1. 1What Are Modular Blockchains? How Do They Scale Networks?
  2. 2Can Stablecoins Earn Interest? How to Generate Real Yield?
  3. 3What Are Short Liquidations? How Can Traders Prevent Them in Crypto?
  4. 4What Is Rehypothecation Risk in Crypto? How to Protect Yourself
  5. 5What Is pERC20? How Does This Ethereum Token Standard Work?
About Us
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
English
About Us
+
  • About BitKan
  • Contact Us
  • Announcements
  • VIP Program
  • BitKan Ambassador
  • Institutional Services
Products
+
  • Spot
  • Futures
  • Crypto Prices
  • Learn
  • News
  • Markets
  • How to Buy Crypto
  • BTC to USD Calculator
  • Reward
Help
+
  • Help Center
  • Email Us
  • Live Chat
  • Download APP
  • Listing Application
  • Buy Bitcoin
  • Buy Ethereum
  • Buy Dogecoin
  • Buy Altcoins
Terms
+
  • Terms of Use
  • Privacy Policy
  • Trading Rules
  • Fee
K-Site
+
  • Twitter
  • Facebook
  • Telegram
  • YouTube
  • Instagram
  • Medium
  • Linkedin
@2012-2026 BITKAN.com