Ledger says attacker conducted phishing attack on former employee
The Ledger attacker was able to upload the malicious code to ConnectKit after phishing a former Ledger employee
Today’s attack on crypto hardware firm Ledger was traced to an ex-employee who “fell victim to a phishing attack that gained access to their NPMJS account” in an email to Blockworks.
The code was then published to ConnectKit. A fix, according to Ledger, was deployed roughly 40 minutes after they were alerted but not before the malicious code was active for five hours.
The address was connected to a malicious code found in Ledger’s ConnectKit software libraries early Thursday. ConnectKit connects blockchain apps with Ledger devices.
WalletConnect was able to disable the “rogue project.” Chainalysis posted the address and Tether CEO Paolo Ardoino said his team froze the Ledger exploiter address.
Ledger told Blockworks that it is working with customers impacted by the attack as well as law enforcement to track the attacker.
The attack led to SushiSwap and Revoke.cash taking their front-end web apps offline. As Blockworks previously reported, Revoke.cash was impacted by the attack. SushiSwap warned users to avoid interacting with the Sushi page.
Ledger, following the warnings across social media, previously updated that it was able to replace the malicious file with the genuine one.
“In the meantime, we’d like to remind the community to always Clear Sign your transactions — remember that the addresses and the information presented on your Ledger screen is the only genuine information,” Ledger continued.
The hardware firm added that users should stop the transaction “immediately” if there’s a difference between the Ledger device screen and the screen on a computer or phone.
Don’t miss the next big story – join our free daily newsletter .
- Ledger
- Phishing
- scam
- sushiswap
- Tether
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
South Korea's major shift in cryptocurrency policy: allowing corporations to open real-name cryptocurrency accounts
This policy marks South Korea's official opening of the virtual asset market to institutional investors.
QOVVO.IO Announces the Open Beta Launch of its Global P2P Crypto Lending Platform
![](https://img.bgstatic.com/multiLang/image/social/b001481bc4735fa538cb681f295968c81739486657175.jpg)
Coinbase's full-year revenue reaches $6.1 billion, more than double from 2023
Quarterly revenue of $2.3 billion was up significantly from $953.7 million in the same period last year.COIN shares are up 16% in 2025 and up about 112% over the past year.
![](https://img.bgstatic.com/multiLang/image/social/9efac6a73ed8ef50818d5ed9ef9b33d51739484693340.jpg)
Trump-backed World Liberty Financial’s MicroStrategy-like token reserve is ‘mostly a clever grift,’ Two Prime CEO says
World Liberty Financial’s new strategic token reserve aims to support major cryptocurrencies like Bitcoin and Ethereum, potentially giving renewed utility to its struggling WLFI governance token.Critics argue that WLFI’s structure allows the Trump family to profit from political influence while offering no direct claims to the reserve for token holders.
![](https://img.bgstatic.com/multiLang/image/social/d3a2ecdcc092566fc489e47e0780c45a1739484692985.jpg)
Trending news
MoreCrypto prices
More![Bitcoin](https://img.bgstatic.com/multiLang/coinPriceLogo/bitcoin.png)
![Ethereum](https://img.bgstatic.com/multiLang/coinPriceLogo/ethereum.png)
![XRP](https://img.bgstatic.com/multiLang/coinPriceLogo/ripple.png)
![Tether USDt](https://img.bgstatic.com/multiLang/coinPriceLogo/0208496be4e524857e33ae425e12d4751710262904978.png)
![BNB](https://img.bgstatic.com/multiLang/coinPriceLogo/binance.png)
![Solana](https://img.bgstatic.com/multiLang/coinPriceLogo/solana.png)
![USDC](https://img.bgstatic.com/multiLang/coinPriceLogo/usdc.png)
![Dogecoin](https://img.bgstatic.com/multiLang/coinPriceLogo/dogecoin.png)
![Cardano](https://img.bgstatic.com/multiLang/coinPriceLogo/cardano.png)
![TRON](https://img.bgstatic.com/multiLang/coinPriceLogo/tron.png)