SushiSwap CTO Discloses Compromise of Web3 Connector
SushiSwap Chief Technical Officer Mathew Lilley has revealed that a widely used web3 connector within Ledger’s delivery network has been compromised. This breach has allowed for the injection of malicious code into multiple decentralized applications (dapps). According to Lookonchain, the hacker stole $484,000 in assets, including 4.334 Ether, and the Angel Drainer phishing scam currently holds $363,000 worth of assets. Tether has frozen the exploiter’s address, effectively ending the scam.
Removal of Malicious Provider
Lilley explains that Ledger’s content delivery network was compromised, resulting in the loading of JavaScript from the compromised network. The compromised Ledger connector library, which is widely used by various dapps under Ledger’s supervision, has been equipped with a wallet drainer. Although assets may not be automatically drained from users’ accounts, prompts from browser wallets like MetaMask could potentially grant malicious actors access to the assets.
Ledger Takes Action and Warns Users
Ledger has identified and removed the malicious version of the Ledger Connect Kit. The company advises users to exercise caution and refrain from interacting with dapps temporarily. Ledger assures users that their Ledger devices and Ledger Live remain secure with no compromise detected.
An Ongoing Target
This incident is not the first time Ledger has been targeted by malicious acts. In November 2023, a fraudulent application named Ledger Live Web3 caused users to lose $800,000 by imitating the legitimate Ledger Live app.
Hot Take: Protecting Your Crypto Assets
It is crucial to stay vigilant and take necessary precautions when dealing with cryptocurrency assets. Incidents like these highlight the importance of using trusted platforms and verifying the authenticity of applications before interacting with them. Always ensure that you are using official and secure channels to protect your valuable crypto assets from potential scams and security breaches.