Live data from Hacker News

Ledger's NPM account has been hacked

github.com

41–50 of 130 posts

Re: Ledger's NPM account has been hacked

#41
post #34

LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…

> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account."

Ouch. A _former_ employee had active credentials to phish for.

> "@Tether_to has frozen the bad actor’s USDT."

Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

Re: Ledger's NPM account has been hacked

#42
How did the exploit work? Obviously it looks really bad for Ledger to keep having these web security failures, but the entire point of a hardware wallet is to make it so that you don't have to rely on the security of the code on your computer.

If the hardware wasn't compromised (sounds like this was just JS), then there was no way for the exploit to take anyone's private key. It sounds to me like the exploit would work by getting you to sign a transaction that would transfer out the funds, without the attacker ever getting your key.

The only way this is possible is if users are signing transactions on their Ledger without looking at them.

And this is place where the Ethereum community needs to look in the mirror. Blind signing is the default for using Ethereum with a Ledger. I'm not sure the technical reasons behind this, but I do happen to know that much of the information that gets signed is in very convoluted formats (meta transactions etc). This is not the case everywhere. Other ecosystems, like Cosmos, present the information to be signed in a plain text format that you can scroll through on the Ledger's screen before you sign it.

Ethereum needs to put some serious effort into making sure that anything that gets signed can be viewed in a human-readable format before signing. Until then, hardware wallets are security theater.

Re: Ledger's NPM account has been hacked

#43
post #34

LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…

$610k drained: https://twitter.com/zachxbt/status/1735292040986886648

Re: Ledger's NPM account has been hacked

#45
post #5

NPM forces 2fa, so I’m curious what the scenario was here. Was a committers phone compromised?

Github action

Actually worse than that, former employee phished for credentials, per Ledger themselves. Underlying cause is utter incompetence by company, 4th strike.

Re: Ledger's NPM account has been hacked

#46
post #3

Ledger has been hacked so many times now i've lost count. I remember buying one in 2019, and shortly thereafter all customer data was dumped on the internet endangering everyone who bought one. Then after deep diving the tech i threw it in the trash, it seemed like security theatre product. There's also been so many phishing attempts, fake ledgers sold, bricked ones losing funds, it's total shitshow that ecosystem if…

>I just use isolated cheap laptops and encrypted usb's now. I figure this isn't practical for most end users. Is there an alternative hardware wallet that you think is okay for most people? How do you feel about Trezor?

The modern solution is to use MPC wallets like ZenGo.

Re: Ledger's NPM account has been hacked

#47
post #34

LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…

> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

> Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

I mean, unlimited Tether can be created or destroyed at the whim of some guy with a big button somewhere. The promise of crypto being the embodiment of true distributed governance went out the window with USDT ages ago.

Re: Ledger's NPM account has been hacked

#48

> Discover what security feels like Quote from their sales site.

Feels pretty apt honestly. This is about how secure I feel using modern technology. The only thing that makes me ok using a bank is knowing I can go ask a human being to chase my money down when it vanishes suddenly. There's even a non-zero chance they get it back to me!

Re: Ledger's NPM account has been hacked

#50
post #37
post #7

Earlier quoted context omitted.

The Github action leaked the creds, seemingly via a log. Looks like that action has been in use for ~4 months.

Source? Their twitter says "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." And Github Actions automatically redacts the secret in the log

You are right, I should have waited for the postmortem.. it appeared the likely way because the secret was in the release pipeline env.

However.. something doesn't add up. There is no chance that a malicious actor gained access and in a couple of hours put together this exploit. Or, I can't see someone putting together this exploit, THEN trying to spear-phish in hope of getting lucky and pressing the button.

Post reply on HN