Ledger Connect Kit Hack
What happened
On December 14, 2023, an attacker published malicious versions of the Ledger Connect Kit, a JavaScript library that many EVM dApps load at runtime to connect to Ledger devices. Ledger said a former employee was phished and the attacker used that person's npm access, which had not been revoked at offboarding, to publish versions 1.1.5, 1.1.6 and 1.1.7. The injected code contained the Angel Drainer kit and made dApp users sign transactions that drained their wallets.
Lookonchain estimated about $484,000 was stolen, and Blockaid's CEO put impacted funds at hundreds of thousands of dollars within the first two hours. Ledger did not publish a figure. Ledger deployed a genuine version (1.1.8) about 40 minutes after it learned of the attack, but CDN caching kept the malicious file available for about five hours in total; Ledger estimated active draining lasted under two hours. WalletConnect disabled the rogue project used to route funds, and Tether froze the attacker's USDT. Ledger said the attacker never had access to its infrastructure, its code repositories or the dApps themselves.
How it happened
- A former Ledger employee fell for a phishing attack that gave the attacker a session token and an API key for their npm account, bypassing 2FA. The account still had publish rights because npm access had not been manually revoked at offboarding.
- Between 08:49 and 10:37 UTC on December 14, 2023 the attacker published malicious
@ledgerhq/connect-kitversions 1.1.5, 1.1.6 and 1.1.7 containing Angel Drainer. - dApps that used Connect-Kit-loader pulled the newest package from the CDN automatically, so the drainer ran inside their front-ends without any change by the dApp teams.
- The drainer asked users to sign
approve/permitmessages for tokens and NFTs, or fakeclaimand transfer transactions for native coins, routing assets through a rogue WalletConnect project. Stolen funds were split about 85% to the attacker and 15% to Angel Drainer. - Ledger learned of the attack at about 12:45 UTC and shipped a fix around 13:18 UTC. WalletConnect disabled the rogue project and Tether froze the attacker's USDT at about 13:55 UTC.
Protocol details
Evidence
- report Security Incident Report (Ledger, Dec 20, 2023) ledger.com
- analysis DeFiLlama defillama.com
- analysis Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code (CoinDesk, Dec 14, 2023) coindesk.com
- analysis Ledger Connect Kit Breach: Hacker Siphons $484K, Company Rolls Out Version 1.1.8 (Bitcoin.com News) news.bitcoin.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.