Earlier quoted context omitted.
>I just use isolated cheap laptops and encrypted usb's now. I figure this isn't practical for most end users. Is there an alternative hardware wallet that you think is okay for most people? How do you feel about Trezor?
Coldcard! https://coldcard.com/
Ledger's NPM account has been hacked
31–40 of 130 posts
Re: Ledger's NPM account has been hacked
#32NPM forces 2fa, so I’m curious what the scenario was here. Was a committers phone compromised?
Re: Ledger's NPM account has been hacked
#33Earlier quoted context omitted.
This is exactly why GitHub support OpenID Connect, https://docs.github.com/en/actions/deployment/security-harde... , so that long-lived secrets don't need to be present as part of the build. I'm not sure if NPM supports OIDC, which would be ironic given that both GitHub and NPM are owned by Microsoft.
Why would that be ironic?
Re: Ledger's NPM account has been hacked
#34FINAL TIMELINE AND UPDATE TO CUSTOMERS:
4:49pm CET:
Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.
The investigation continues, here is the timeline of what we know about the exploit at this moment:
- This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account. - The attacker published a malicious version of the Ledger Connect Kit (affecting versions 1.1.5, 1.1.6, and 1.1.7). The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet. - Ledger’s technology and security teams were alerted and a fix was deployed within 40 minutes of Ledger becoming aware. The malicious file was live for around 5 hours, however we believe the window where funds were drained was limited to a period of less than two hours. - Ledger coordinated with @WalletConnect who quickly disabled the the rogue project. - The genuine and verified Ledger Connect Kit version 1.1.8 is now propagating and is safe to use. - For builders who are developing and interacting with the Ledger Connect Kit code: connect-kit development team on the NPM project are now read-only and can’t directly push the NPM package for safety reasons. - We have internally rotated the secrets to publish on Ledger’s GitHub. - Developers, please check again that you’re using the latest version, 1.1.8. - Ledger, along with @Walletconnect and our partners, have reported the bad actor’s wallet address. The address is now visible on @chainalysis . @Tether_to has frozen the bad actor’s USDT. - We remind you to always Clear Sign with your Ledger. What you see on the Ledger screen is what you actually sign. If you still need to blind sign, use an additional Ledger mint wallet or parse your transaction manually. - We are actively talking with customers whose funds might have been affected, and working proactively to help those individuals at this time. - We are filing a complaint and working with law enforcement on the investigation to find the attacker. - We’re studying the exploit in order to avoid further attacks. We believe the attacker’s address where the funds were drained is here: 0x658729879fca881d9526480b82ae00efc54b5c2d
Thank you to @WalletConnect , @Tether_io, @Chainalysis , @zachxbt , and the whole community that helped us and continue to help us identify and solve this attack.
Security will always prevail with the help of the whole ecosystem.
Re: Ledger's NPM account has been hacked
#35One of the comments on the github issue... https://github.com/LedgerHQ/connect-kit/issues/29 "The @ledgerhq/connect-kit-loader allows dApps to load Connect Kit at runtime from a CDN so that we can improve the logic and UI without users having to wait for wallet libraries and dApps updating package versions and releasing new builds. This looks like an extremely dangerous approach now, if I understand it correctly, con…
Re: Ledger's NPM account has been hacked
#36One of the comments on the github issue... https://github.com/LedgerHQ/connect-kit/issues/29 "The @ledgerhq/connect-kit-loader allows dApps to load Connect Kit at runtime from a CDN so that we can improve the logic and UI without users having to wait for wallet libraries and dApps updating package versions and releasing new builds. This looks like an extremely dangerous approach now, if I understand it correctly, con…
Is there even an alternative? Once you can inject arbitrary code into a library that a web app loads and executes (except if it’s in an iFrame), it’s game over, no?
Re: Ledger's NPM account has been hacked
#37NPM forces 2fa, so I’m curious what the scenario was here. Was a committers phone compromised?
The Github action leaked the creds, seemingly via a log. Looks like that action has been in use for ~4 months.
Their twitter says "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account."
And Github Actions automatically redacts the secret in the log
Re: Ledger's NPM account has been hacked
#38Ledger has been hacked so many times now i've lost count. I remember buying one in 2019, and shortly thereafter all customer data was dumped on the internet endangering everyone who bought one. Then after deep diving the tech i threw it in the trash, it seemed like security theatre product. There's also been so many phishing attempts, fake ledgers sold, bricked ones losing funds, it's total shitshow that ecosystem if…
>I just use isolated cheap laptops and encrypted usb's now. I figure this isn't practical for most end users. Is there an alternative hardware wallet that you think is okay for most people? How do you feel about Trezor?
Re: Ledger's NPM account has been hacked
#39LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…
2) Former employee has signing/push auth on super high value repo?
3) Single person has signing/push auth on super high value repo?
.com