Ledger's NPM account has been hacked
61–70 of 130 posts
Re: Ledger's NPM account has been hacked
#62LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…
> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?
We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically.
It is a shame how far crypto has fallen culturally that this stablecoin business is some niche story. Most people are in it for the money, but many good people are not.
Re: Ledger's NPM account has been hacked
#63LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…
1/ Handling the custody of secrets by the company. The attackers first attacked and accessed a former Ledger employee with official Ledger account secrets. This is where secrets were mismanaged since the actual company secrets should never be in the hands of former employees.
2/ The attack could occur on an actual employee so they should employ ways to be protected against this kind of attack.
3/ The use of CDNs should have security measures in place. This is one of the most common attacks nowadays.
Re: Ledger's NPM account has been hacked
#64I thought the whole point of ledger was that it's a physical wallet that can't easily be compromised. Not your keys not your crypto and all that?
Re: Ledger's NPM account has been hacked
#65LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…
> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?
The base level assets, like ETH and BTC, cannot be frozen like this, although centralized exchanges will often blacklist addresses (and the chain of custody) involved in major exploits.
Re: Ledger's NPM account has been hacked
#66Earlier quoted context omitted.
> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?
You can have gradations of control. USDT and USDC are centrally managed. We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically. It is a shame how far crypto has fallen culturally that this st…
Re: Ledger's NPM account has been hacked
#67Earlier quoted context omitted.
> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?
You can have gradations of control. USDT and USDC are centrally managed. We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically. It is a shame how far crypto has fallen culturally that this st…
I think it's fine to have a spectrum of centralized assets and decentralized assets represented as tokens. Blockchains are public, permissionless, ledgers.
Re: Ledger's NPM account has been hacked
#68LOL, I initially thought this was Ledger, the command-line personal finance management software, and was worried that it was actually something important.
Re: Ledger's NPM account has been hacked
#69Earlier quoted context omitted.
You can have gradations of control. USDT and USDC are centrally managed. We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically. It is a shame how far crypto has fallen culturally that this st…
There is no possible way that USDT is backed one-to-one. It just isn't. If it were, it would have a simple audit trail that they would publish. They don't because it isn't. It's a scam that will at some point unravel, and everyone will lose their shirts because of "many good people" lol.
Re: Ledger's NPM account has been hacked
#70Earlier quoted context omitted.
The Github action leaked the creds, seemingly via a log. Looks like that action has been in use for ~4 months.
Automated publishing without a human involved kind of kills the whole point of 2FA anyway. It is kind of funny that the crypto world of multi sigs relies on blind trust of unverified UI components.
Let's also not forget that every other website on the planet that relies on npm also relies on the blind trust of unverified UI components. This isn't just silo'd to crypto.