Live data from Hacker News

Ledger's NPM account has been hacked

github.com

61–70 of 130 posts

Re: Ledger's NPM account has been hacked

#62
post #34

LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…

> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

You can have gradations of control. USDT and USDC are centrally managed.

We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically.

It is a shame how far crypto has fallen culturally that this stablecoin business is some niche story. Most people are in it for the money, but many good people are not.

Re: Ledger's NPM account has been hacked

#63
post #34

LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…

There are at least three type of vulnerabilities here:

1/ Handling the custody of secrets by the company. The attackers first attacked and accessed a former Ledger employee with official Ledger account secrets. This is where secrets were mismanaged since the actual company secrets should never be in the hands of former employees.

2/ The attack could occur on an actual employee so they should employ ways to be protected against this kind of attack.

3/ The use of CDNs should have security measures in place. This is one of the most common attacks nowadays.

Re: Ledger's NPM account has been hacked

#64
post #61

I thought the whole point of ledger was that it's a physical wallet that can't easily be compromised. Not your keys not your crypto and all that?

This was a UI popup that got injected into the middleware provided by Ledger that is used to make it easy for apps to prompt Ledger users for a signature. The keys aren't compromised by this attack, this is more similar to a phishing attack, but via supply chain to increase fake legitimacy.

Re: Ledger's NPM account has been hacked

#65
post #34

LOL https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim t…

> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

Tokens are fully programmable, so you can encode whatever logic you want in them, including freezing if you want that functionality. This is mainly done in dollar-backed stable coins.

The base level assets, like ETH and BTC, cannot be frozen like this, although centralized exchanges will often blacklist addresses (and the chain of custody) involved in major exploits.

Re: Ledger's NPM account has been hacked

#66

Earlier quoted context omitted.

> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

You can have gradations of control. USDT and USDC are centrally managed. We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically. It is a shame how far crypto has fallen culturally that this st…

There is no possible way that USDT is backed one-to-one. It just isn't. If it were, it would have a simple audit trail that they would publish. They don't because it isn't. It's a scam that will at some point unravel, and everyone will lose their shirts because of "many good people" lol.

Re: Ledger's NPM account has been hacked

#67

Earlier quoted context omitted.

> "This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account." Ouch. A _former_ employee had active credentials to phish for. > "@Tether_to has frozen the bad actor’s USDT." Wasn't like, >30% of the point of crypto to not allow people to do this sort of high-level/centralized freezing?

You can have gradations of control. USDT and USDC are centrally managed. We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically. It is a shame how far crypto has fallen culturally that this st…

I don't think MakerDAO ever integrated USDT as collateral, but they did integrate USDC. It's unfortunate DAI is not fully decentralized, but the best fully decentralized stable coin efforts (like RAI and LUSD) often suffer from a capital efficiency problem.

I think it's fine to have a spectrum of centralized assets and decentralized assets represented as tokens. Blockchains are public, permissionless, ledgers.

Re: Ledger's NPM account has been hacked

#69

Earlier quoted context omitted.

You can have gradations of control. USDT and USDC are centrally managed. We used to have DAI, which was fully decentralized and over-collatoralized by Ethereum tokens (the native currency of the platform DAI is rooted on) - but the founder mysteriously died as the DAO was taken over and made to begin collateralizing DAI against USDC and USDT, ironically. It is a shame how far crypto has fallen culturally that this st…

There is no possible way that USDT is backed one-to-one. It just isn't. If it were, it would have a simple audit trail that they would publish. They don't because it isn't. It's a scam that will at some point unravel, and everyone will lose their shirts because of "many good people" lol.

They do post audits on the regular: https://tether.to/en/transparency/#reports

Re: Ledger's NPM account has been hacked

#70
post #22
post #7

Earlier quoted context omitted.

The Github action leaked the creds, seemingly via a log. Looks like that action has been in use for ~4 months.

Automated publishing without a human involved kind of kills the whole point of 2FA anyway. It is kind of funny that the crypto world of multi sigs relies on blind trust of unverified UI components.

Technically, it is just the frontends. You can always interact with the contracts directly and that can't ever be shut down (if you know what you're doing). Can you do that with your bank?

Let's also not forget that every other website on the planet that relies on npm also relies on the blind trust of unverified UI components. This isn't just silo'd to crypto.

Post reply on HN