Bitcoin Forum
April 30, 2024, 07:35:31 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 »  All
  Print  
Author Topic: IMPORTANT: Ledger ConnectKit Library has been Compromised with a drainer.  (Read 522 times)
nelson4lov (OP)
Hero Member
*****
Offline Offline

Activity: 2058
Merit: 791


Top Crypto Casino


View Profile
December 14, 2023, 01:33:08 PM
Last edit: December 14, 2023, 09:09:04 PM by nelson4lov
Merited by NotATether (7), OmegaStarScream (5), vapourminer (4), pooya87 (4), DdmrDdmr (4), cygan (3), Pmalek (2), hosseinimr93 (2), suchmoon (1), BitMaxz (1), criptoevangelista (1)
 #1

Apparently, Ledger is in the news again for the wrong reasons.

At first, SuchiSwap CTO (one of the leading DEXs) made a tweet about the suspected vulnerability.



The primary issue is that the Ledger ConnectKit NPM package Library that is used across majority of decentralized applications was updated few hours ago with malicious code (drainer):



How come?

It looks like the NPM key was leaked via a github action  which means Anyone can invoke the action via a PR on Ledger's GitHub Orgs, then leak that key by crafting a malicious package.json.




Right now, any user interacting with any and all Dapps could potentially be exposed to the vulnerability and end up losing all funds to drainers. According to my research so far, it doesn't include users who are just using Ledger for day-to-day transfers with no interactions and prior interactions before the vulnerability was disclosed appears to good.

Side note: This only shows how poorly the Ledger team takes security and their continued negligence of the security of their products and services.

Update #1: Ledger has confirmed the vulnerability report:
Quote
🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨

A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.

Your Ledger device and Ledger Live were not compromised.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
1714505731
Hero Member
*
Offline Offline

Posts: 1714505731

View Profile Personal Message (Offline)

Ignore
1714505731
Reply with quote  #2

1714505731
Report to moderator
Be very wary of relying on JavaScript for security on crypto sites. The site can change the JavaScript at any time unless you take unusual precautions, and browsers are not generally known for their airtight security.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
rhomelmabini
Hero Member
*****
Offline Offline

Activity: 2002
Merit: 578


View Profile
December 14, 2023, 01:46:00 PM
 #2

I don't know if I'll be affected on it but when I saw the news I definitely run to revoke.cash and definitely I get to signed there but then suddenly it goes with another website so I closed it like "Vercel" or something, can't remember. Do I have to worry for that?
criptoevangelista
Full Member
***
Online Online

Activity: 238
Merit: 501


Siga sempre em frente! always move forward!


View Profile
December 14, 2023, 01:48:09 PM
 #3

The important thing now is not to interact with absolutely anything on chain until the problems are resolved.

again problems with the ledger. I use a ledger nano X and from now on I will consider getting a new hardwallet.

nelson4lov (OP)
Hero Member
*****
Offline Offline

Activity: 2058
Merit: 791


Top Crypto Casino


View Profile
December 14, 2023, 01:48:42 PM
 #4

I don't know if I'll be affected on it but when I saw the news I definitely run to revoke.cash and definitely I get to signed there but then suddenly it goes with another website so I closed it like "Vercel" or something, can't remember. Do I have to worry for that?

Imo, As long as you didn't sign any of the prompts, you should be good to good. Unless you signed any message or interactions with your signature, you should be good to go. But still, remain vigilant till we have a full report.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
rhomelmabini
Hero Member
*****
Offline Offline

Activity: 2002
Merit: 578


View Profile
December 14, 2023, 01:56:28 PM
 #5

I don't know if I'll be affected on it but when I saw the news I definitely run to revoke.cash and definitely I get to signed there but then suddenly it goes with another website so I closed it like "Vercel" or something, can't remember. Do I have to worry for that?
Imo, As long as you didn't sign any of the prompts, you should be good to good. Unless you signed any message or interactions with your signature, you should be good to go. But still, remain vigilant till we have a full report.
You mean if I didn't signed anything like the "signed message" that we see on our wallet? I think I did, because I was on the right site of revoke.cash but then suddenly it goes for another site and it asks to login with my GitHub etc., monitoring my wallet but nothing is happening at the moment, do I have to move anything then?
OmegaStarScream
Staff
Legendary
*
Offline Offline

Activity: 3458
Merit: 6105



View Profile
December 14, 2023, 01:56:46 PM
 #6

What does this really mean though? Is this the library used by dapps to allow users to connect directly to the Ledger, instead of using MetaMask as an intermediary?  I don't believe I have seen many sites using that lately?

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
nelson4lov (OP)
Hero Member
*****
Offline Offline

Activity: 2058
Merit: 791


Top Crypto Casino


View Profile
December 14, 2023, 02:00:22 PM
 #7

What does this really mean though? Is this the library used by dapps to allow users to connect directly to the Ledger, instead of using MetaMask as an intermediary?  I don't believe I have seen many sites using that lately?

The Library is used by various dapps for their "Connect Wallet" modal that users can click to connect their wallets to these dapps in other to facilitate interactions. One of the libraries (Ledger's ConnectKit) that is used in most frontends was compromised.

The issue mainly affects users that uses frontends for interactions.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
criptoevangelista
Full Member
***
Online Online

Activity: 238
Merit: 501


Siga sempre em frente! always move forward!


View Profile
December 14, 2023, 02:01:24 PM
 #8

I don't know if I'll be affected on it but when I saw the news I definitely run to revoke.cash and definitely I get to signed there but then suddenly it goes with another website so I closed it like "Vercel" or something, can't remember. Do I have to worry for that?
Imo, As long as you didn't sign any of the prompts, you should be good to good. Unless you signed any message or interactions with your signature, you should be good to go. But still, remain vigilant till we have a full report.
You mean if I didn't signed anything like the "signed message" that we see on our wallet? I think I did, because I was on the right site of revoke.cash but then suddenly it goes for another site and it asks to login with my GitHub etc., monitoring my wallet but nothing is happening at the moment, do I have to move anything then?

I would switch to a secure wallet so I don't have to worry about this anymore.

Kryptowerk
Legendary
*
Offline Offline

Activity: 2030
Merit: 1401


Disobey.


View Profile
December 14, 2023, 02:04:26 PM
 #9

Thanks for the warning and updates @nelson4lov

Soon I can start an info thread with a list of all the Ledger f-ups that happened over the years. It's getting longer and longer.

I'm not up-to-date with all these web3 dApp stuff - what actually is affected here? Are we talking about swap-dApps and Defi-stuff or anything else?
Also, does this only affect tokens on the Ethereum chain or also others?

Get educated about Bitcoin. Check out Andreas Antonopoulos on Youtube. An old but gold talk: https://www.youtube.com/watch?v=rc744Z9IjhY

Daniel Schmachtenberger on The Meta-Crisis: https://www.youtube.com/watch?v=4kBoLVvoqVY&t=288s One of the most important talks about the current state of this planet. Go check it out.
btc_penguin
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
December 14, 2023, 02:06:47 PM
 #10

Anyone knows whether Electrum uses the library as well?
nelson4lov (OP)
Hero Member
*****
Offline Offline

Activity: 2058
Merit: 791


Top Crypto Casino


View Profile
December 14, 2023, 02:22:40 PM
 #11

Thanks for the warning and updates @nelson4lov

Soon I can start an info thread with a list of all the Ledger f-ups that happened over the years. It's getting longer and longer.

I'm not up-to-date with all these web3 dApp stuff - what actually is affected here? Are we talking about swap-dApps and Defi-stuff or anything else?
Also, does this only affect tokens on the Ethereum chain or also others?

No tokens or core Ethereum protocol was affected. The Ledger ConnectKit Library is a common Library that is usually used for connecting wallets in order to interact with Dapps (staking, swapping, Money markets, etc). Being compromised means any user that connects to any decentralized application via a "connect wallet" kit is likely to get drained since there is malicious drainer embedded in the library being used.

This is a case of a library being popularly used in frontends getting compromised.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
rhomelmabini
Hero Member
*****
Offline Offline

Activity: 2002
Merit: 578


View Profile
December 14, 2023, 02:49:10 PM
 #12

I don't know if I'll be affected on it but when I saw the news I definitely run to revoke.cash and definitely I get to signed there but then suddenly it goes with another website so I closed it like "Vercel" or something, can't remember. Do I have to worry for that?
Imo, As long as you didn't sign any of the prompts, you should be good to good. Unless you signed any message or interactions with your signature, you should be good to go. But still, remain vigilant till we have a full report.
You mean if I didn't signed anything like the "signed message" that we see on our wallet? I think I did, because I was on the right site of revoke.cash but then suddenly it goes for another site and it asks to login with my GitHub etc., monitoring my wallet but nothing is happening at the moment, do I have to move anything then?
I would switch to a secure wallet so I don't have to worry about this anymore.
The drainer doesn't come from the signing message but was on the WalletConnect modal and the drainer was faking that popup modal with different appearance during the dApp connection phase. I already identify that during my interaction with revoke.cash they already made the site offline but I'm still being vigilant for further announcement.

Not necessarily I would switch considering there has been some staked assets on my wallet and the advisory that no interaction yet on any dApps means I won't be able to get them out as well. Still monitoring the incident and glad we have huge helpful community not just here but on Twitter/X as well.
SquirrelJulietGarden
Hero Member
*****
Offline Offline

Activity: 1302
Merit: 726



View Profile
December 14, 2023, 03:01:07 PM
 #13

The Library is used by various dapps for their "Connect Wallet" modal that users can click to connect their wallets to these dapps in other to facilitate interactions. One of the libraries (Ledger's ConnectKit) that is used in most frontends was compromised.

The issue mainly affects users that uses frontends for interactions.
dApps and smart contracts are not smart all all as they can be exploited by scammers.

I don't want to touch them too much and if I use dApp and smart contract with interactions, I will create a new wallet with small fund for it. If anyone use only one wallet, store all fund there but are ready to explore around new platforms, dApps, smart contracts, such interactions are risky and drain all money in that wallet.

I don't mind about Ledger and the advice is general for practice with fund, wallet and any interaction that can steal your money.

███▄▀██▄▄
░░▄████▄▀████ ▄▄▄
░░████▄▄▄▄░░█▀▀
███ ██████▄▄▀█▌
░▄░░███▀████
░▐█░░███░██▄▄
░░▄▀░████▄▄▄▀█
░█░▄███▀████ ▐█
▀▄▄███▀▄██▄
░░▄██▌░░██▀
░▐█▀████ ▀██
░░█▌██████ ▀▀██▄
░░▀███
▄▄██▀▄███
▄▄▄████▀▄████▄░░
▀▀█░░▄▄▄▄████░░
▐█▀▄▄█████████
████▀███░░▄░
▄▄██░███░░█▌░
█▀▄▄▄████░▀▄░░
█▌████▀███▄░█░
▄██▄▀███▄▄▀
▀██░░▐██▄░░
██▀████▀█▌░
▄██▀▀██████▐█░░
███▀░░
gunhell16
Sr. Member
****
Offline Offline

Activity: 1680
Merit: 474



View Profile
December 14, 2023, 03:03:56 PM
 #14

That's worrying, I even ordered a hardware wallet and I'm just waiting for it to arrive, really the exploitative person will do anything when there is an opportunity to attack other people to steal.

I hope it can be resolved properly and they can innovate more securely without disturbing the HW holders in these situations we have today. How many times have these issues happened? Wasn't there something before in the ledger too, right?

.
SPIN

       ▄▄▄██████████▄▄▄
     ▄███████████████████▄
   ▄██████████▀▀███████████▄
   ██████████    ███████████
 ▄██████████      ▀█████████▄
▄██████████        ▀█████████▄
█████████▀▀   ▄▄    ▀▀▀███████
█████████▄▄  ████▄▄███████████
███████▀  ▀▀███▀      ▀███████
▀█████▀          ▄█▄   ▀█████▀
 ▀███▀   ▄▄▄  ▄█████▄   ▀███▀
   ██████████████████▄▄▄███
   ▀██████████████████████▀
     ▀▀████████████████▀▀
        ▀▀▀█████████▀▀▀
.
RIUM
.
███
███
███
███
███
███
███
███
███
███
███
███
SAFE GAMES
WITH WITHDRAWALS
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
.
███
███
███
███
███
███
███
███
███
███
███
███
▄▀▀▀











▀▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
SIGN UP


▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▄











▄▄▄▀
KiaKia
Sr. Member
****
Offline Offline

Activity: 658
Merit: 386



View Profile WWW
December 14, 2023, 03:13:49 PM
 #15

It just get to my notice right now, and I already created another topic, this is so messed up with Ledger, I am glad that I am not using the Nano that was sent to me by a friend as a gift, I just don't feel safe using the wallet.

I think the best solution is to avoid connecting your hardware wallet to anything, if you want to sell, send from your hardware wallet to a hot wallet first and use the hot wallet to connect to anything, correct me if I am wrong? I believe this is even a good advice for all hardware wallet users.

As those who are trapped use their ledger to connect, I don't do this even while I am using a air gapped hardware wallet.

.
SPIN

       ▄▄▄██████████▄▄▄
     ▄███████████████████▄
   ▄██████████▀▀███████████▄
   ██████████    ███████████
 ▄██████████      ▀█████████▄
▄██████████        ▀█████████▄
█████████▀▀   ▄▄    ▀▀▀███████
█████████▄▄  ████▄▄███████████
███████▀  ▀▀███▀      ▀███████
▀█████▀          ▄█▄   ▀█████▀
 ▀███▀   ▄▄▄  ▄█████▄   ▀███▀
   ██████████████████▄▄▄███
   ▀██████████████████████▀
     ▀▀████████████████▀▀
        ▀▀▀█████████▀▀▀
.
RIUM
.
███
███
███
███
███
███
███
███
███
███
███
███
SAFE GAMES
WITH WITHDRAWALS
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
       ▄▀▀▀▀▀▀▄▄▄▄
 ▄▀▀▀▀▀▀▀▀▀▀▀▀▄  ▀▀▄
█    ▄         █   ▀▌
█   █ █        █    ▌
█      ▄█▄     █   ▐
█     ▄███▄    █   ▌
█    ███████   █  ▐
█    ▀▀ █ ▀▀   █  ▌
█     ▄███▄    █ ▐
█              █▐▌
█        █ █   █▌
 ▀▄▄▄▄▄▄▄▄█▄▄▄▀
.
███
███
███
███
███
███
███
███
███
███
███
███
▄▀▀▀











▀▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
SIGN UP


▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▄











▄▄▄▀
cheezcarls
Hero Member
*****
Offline Offline

Activity: 2254
Merit: 658


Revolutionized copy gaming platform


View Profile
December 14, 2023, 03:21:16 PM
 #16

Most of the important assets are in my Ledger, but I’ve never connect it to Dapps as it’s only treated for long term storage. These hackers are getting smarter overtime, so DeFi and Web3 are still young and has long ways to go because of one of their major weakness which is the cybersecurity side.

On top of that, I have disconnected my burner Metamask wallet in all of the sites that I have interacted.

It looks like that the wallets implementing the traditional seed phrase and private key model are the most vulnerable of all and are targeted by the hackers whether if it’s cold or hot non-custodial type.

Pla
                             ▄██████████▌
████             ▐███████████▌
  ████         ▐████    ███
   ▐████     ▐████     ███       ███      ▂▃▅
     ████    ████        ███      ███████
        ███    ████        ███      ███████
         ▐██    ████        ███      ███          
                 █████         ███      ███
              █████▌         ███      ███
           █████▌            ███      ███
     ██████▌
███████
ade.win
██            ██
██            ██
██            ██
██         ██
  ▌         ██
  ▌   ██    ██
        ██    ██
        ██      ▌
        ██      ▌
        ██
        ██
.R E V O L U T I O N A R Y   C O P Y   G A M I N G   P L A T F O R M  .
██            ██
██            ██
██            ██
██         ██ 
  ▌         ██
  ▌   ██    ██
        ██    ██
        ██      ▌
        ██      ▌
        ██
        ██
█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█
█ ████▀▀▀▀▀███████▀▀▀████ █
█ █████▄  █ ████▀  ▄█████ █
█ ██████▄  █ █▀  ▄███████ █
█ ███████▄  █  ▄█████████ █
█ ████████▄  █ ██████████ █
█ ██████▀  ▄█▄ █ ████████ █
█ ████▀  ▄███▄  █ ███████ █
█ ██▀   ██████▄  █ ██████ █
█ ██▄▄▄████████▄▄▄▄▄█████ █
█▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄█
Play Smart Win Big!
m2017
Legendary
*
Offline Offline

Activity: 1792
Merit: 1303


keep walking, Johnnie


View Profile
December 14, 2023, 03:25:11 PM
 #17

Would you like a little dose of conspiracy theory? Smiley

After this compromise, Ledger will definitely release new firmware for their devices (they can’t help but do this), into which you can integrate any program code directed against the interests of ledger owners (like even more tracking and obtaining personal data or even gaining complete control over their means).

Horror story (they could have pulled this off a long time ago).

But seriously, what can I say. Ledger screwed up again. Happens. I mean, it has happened more than once. We weren't surprised at all. I wonder what the next fakap will be?

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
so98nn
Hero Member
*****
Offline Offline

Activity: 2086
Merit: 603


View Profile
December 14, 2023, 03:25:59 PM
 #18

Thanks for the heads up.

What is the protocol here? Should I control my urge to connect the ledger to a PC and the internet now? My soul purpose for having a Ledger is to store my coins for a very long duration and I rarely connect my Ledger and go live. I have had terrible experiences in the past so I am either not connecting it every day or just rarely synch the new balances, check the updates, and bug fixes only.

Though the news only states we should not be connecting to dApps, what happens if I just connect it normally synch with the network? Because I know if I connect and if there are any updates for let us say wallets of different coins then it will start auto downloainf it. I just don't want to get involve with any of the mess right now when the balance is loaded.
Z-tight
Hero Member
*****
Online Online

Activity: 840
Merit: 1031


Only BTC


View Profile
December 14, 2023, 03:45:20 PM
 #19

Anyone knows whether Electrum uses the library as well?
This is about Ledger and their connector library, i do not know too much about Dapps and how some of them use ledger's connector library, but this has nothing to do with Electrum, even if you have your Electrum connected to your Ledger wallet, just make sure you're running your own node for better privacy and security. Ledger isn't a recommended hardware wallet, so people should not even be using this hardware wallet in the first place.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
cygan
Legendary
*
Offline Offline

Activity: 3136
Merit: 7721


Crypto Swap Exchange


View Profile WWW
December 14, 2023, 04:13:15 PM
Merited by Pmalek (2), vapourminer (1)
 #20

as Metamask announces, this affects not only Ledger users but everyone who uses dapps. at the same time, Metamask has deployed a fix for its users:


https://nitter.net/MetaMask/status/1735318141285085513

and according to this tweet you can see very well how the malicious 'connect wallet' popup menu opens over the original and offers the user various options:


https://nitter.net/apoorvlathey/status/1735281719216071019

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Pages: [1] 2 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!