Ledger: Genuine and verified Ledger Connect Kit version 1.1.8 is now safe to use
Ledger has released the latest update on the vulnerability on the X platform, stating that the genuine and validated Ledger Connect Kit version 1.1.8 has now been spread and can be safely used. For builders who are developing Ledger Connect Kit code and interacting with it: the connect-kit development team on the NPM project is now read-only and cannot directly push NPM packages for security reasons.
In addition, malicious code uses the rogue WalletConnect project to reroute funds to hacker wallets. -Ledger's technical and security teams received alerts and deployed fixes within 40 minutes of Ledger's awareness. The survival time of this malicious file is about 5 hours, but the time window for funds to be depleted is less than two hours.
The team is filing complaints and working with law enforcement to investigate and find the attacker, and is studying the vulnerability to avoid further attacks.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Senate majority leader fast-tracks GENIUS Act to regulate stablecoins
Share link:In this post: Senate majority leader John Thune took steps to fast-track the GENIUS Act. Bill Hagerty may release an updated version of the GENIUS Act soon. Arthur Wilmarth believes the bill is deeply flawed.
Canada’s new Prime Minister will meet Trump to revive trading relations
Share link:In this post: Prime Minister Mark Carney will meet Donald Trump in Washington to address trade tensions. Canada plans to counter US tariffs affecting its key industries like auto and steel. King Charles will open Canada’s new parliament in Ottawa on May 27.
Google gets September court date to begin fight for its ad tech business
Share link:In this post: Google will face a U.S. antitrust trial starting September 22, 2025. The DOJ wants the tech giant to remove its key advertising tools, specifically its publisher ad server and ad exchange tools. The DOJ is attempting to force a sale of the Chrome web browser.

Charles Hoskinson Teases AI Agents Will Testrun Ouroboros Leios
Trending news
MoreCrypto prices
More








