* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, May 23, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    SRM Entertainment Announces $5 Million Private Placement – GlobeNewswire

    SRM Entertainment Secures $5 Million Investment to Fuel Growth!

    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    San Jose eyes creation of entertainments zones with FIFA World Cup, Super Bowl LX on the horizon – The Mercury News

    San Jose Sets Its Sights on Exciting Entertainment Zones Ahead of FIFA World Cup and Super Bowl LX!

    Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

    Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

    Jason Momoa Is Done With Peace in Apple’s ‘Chief of War’ Teaser – Yahoo

    Jason Momoa Embraces Chaos in Gripping Teaser for Apple’s ‘Chief of War’

    AI Entertainment Studio Promise Inks Deal With Google, Raises Investment from Michael Ovitz’s Crossbeam – The Hollywood Reporter

    AI Entertainment Studio Promise Secures Major Deal with Google and Attracts Investment from Michael Ovitz’s Crossbeam!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    InfiMotion Technology launches TL 300 integrated drive system – Automotive Powertrain Technology International

    InfiMotion Technology Unveils Game-Changing TL 300 Integrated Drive System!

    Aera Technology Debuts Decision Intelligence Skill to Navigate Shifting Tariff Dynamics Across Value Chains – Silicon Canals

    Unlocking Success: Aera Technology Launches Innovative Decision Intelligence Skill to Tackle Evolving Tariff Challenges in Value Chains

    Auditory Processing and Psychosocial Improvements with Remote Microphone Technology: An Evidence Review – The Hearing Review

    Unlocking Sound: How Remote Microphone Technology Enhances Auditory Processing and Boosts Psychosocial Well-Being

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Novotech Honored with Triple Win in 2025 Pharmaceutical Technology Excellence Awards – Morningstar

    Novotech Celebrates Triple Triumph at the 2025 Pharmaceutical Technology Excellence Awards!

    Experts Issue Warning on New TSA Technology – Men’s Journal

    Experts Sound Alarm Over New TSA Technology: What You Need to Know

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    SRM Entertainment Announces $5 Million Private Placement – GlobeNewswire

    SRM Entertainment Secures $5 Million Investment to Fuel Growth!

    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    San Jose eyes creation of entertainments zones with FIFA World Cup, Super Bowl LX on the horizon – The Mercury News

    San Jose Sets Its Sights on Exciting Entertainment Zones Ahead of FIFA World Cup and Super Bowl LX!

    Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

    Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

    Jason Momoa Is Done With Peace in Apple’s ‘Chief of War’ Teaser – Yahoo

    Jason Momoa Embraces Chaos in Gripping Teaser for Apple’s ‘Chief of War’

    AI Entertainment Studio Promise Inks Deal With Google, Raises Investment from Michael Ovitz’s Crossbeam – The Hollywood Reporter

    AI Entertainment Studio Promise Secures Major Deal with Google and Attracts Investment from Michael Ovitz’s Crossbeam!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    InfiMotion Technology launches TL 300 integrated drive system – Automotive Powertrain Technology International

    InfiMotion Technology Unveils Game-Changing TL 300 Integrated Drive System!

    Aera Technology Debuts Decision Intelligence Skill to Navigate Shifting Tariff Dynamics Across Value Chains – Silicon Canals

    Unlocking Success: Aera Technology Launches Innovative Decision Intelligence Skill to Tackle Evolving Tariff Challenges in Value Chains

    Auditory Processing and Psychosocial Improvements with Remote Microphone Technology: An Evidence Review – The Hearing Review

    Unlocking Sound: How Remote Microphone Technology Enhances Auditory Processing and Boosts Psychosocial Well-Being

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Novotech Honored with Triple Win in 2025 Pharmaceutical Technology Excellence Awards – Morningstar

    Novotech Celebrates Triple Triumph at the 2025 Pharmaceutical Technology Excellence Awards!

    Experts Issue Warning on New TSA Technology – Men’s Journal

    Experts Sound Alarm Over New TSA Technology: What You Need to Know

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned

December 16, 2023
in Technology
Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned
Share on FacebookShare on Twitter

Cryptocurrency wallet maker Ledger says someone slipped malicious code into one of its JavaScript libraries to steal more than half a million dollars from victims.

The library in question is Connect Kit, which allows DApps – decentralized software applications – to connect to and use people’s Ledger hardware wallets.

Pascal Gauthier, CEO of Ledger, in a public post said a former employee had been duped by a phishing attack, which allowed an unauthorized party to upload a malicious file to the company’s NPM registry account.

“The attacker published a malicious version of the Ledger Connect Kit (affecting versions 1.1.5, 1.1.6, and 1.1.7),” said Gauthier. “The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet.”

The malicious file was what’s known as a “crypto drainer” – it siphons funds from digital wallets. And because dozens of crypto projects utilize the Connect Kit library, the potential financial loss could have been considerable. The damage however was limited because the compromised file was only live for about five hours and active for about two.

During this period, it’s claimed that the attacker managed to obtain more than $610,000 worth of crypto tokens. Revoke.cash, a service for revoking certain crypto transactions – which was affected by the incident – reports losses on the order of $850,000.

According to Gauthier, the attack was addressed within 40 minutes of discovery, the attacker’s blockchain address has been identified, and Tether has frozen the attacker’s Tether tokens. Authorities, he claims, have been notified.

“The authentic and verified version of the Ledger Connect Kit, version 1.1.8, is now in circulation and safe to use,” said Gauthier.

“Safe” may be overstating the case: According to security firm Socket, which provides algorithmic assessments of NPM packages, Connect Kit currently rates 51 out of 100 for Supply Chain Security and 55 out of 100 for Quality.

Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes

Interpol moves against human traffickers who enslave people to scam you online

Crypto crasher Do Kwon’s extradition approved, but destination is unclear

48-nation bloc to crack down on using crypto assets to avoid tax

Gauthier insists standard practice at Ledger is that no one person can deploy code without a multiparty review.

“We have strong access controls, internal reviews, and multi-signature code when it comes to most parts of our development,” he said. “This is the case in 99 percent of our internal systems. Any employee who leaves the company has their access revoked from every Ledger system.”

And yet Ledger’s account of the incident – a former employee surrendered credentials to a phishing scheme, allowing a miscreant to gain access to Ledger’s NPM account to push through bad code – suggests this was one occasion where company security controls fell short.

According to Rosco Kalis, a software engineer for Revoke.cash, Ledger did not have two-factor authentication in place for NPM, which presumably would have prevented the phishing attack from working. What’s more, Kalis claimed Ledger failed to revoke code publication rights for its former employee.

Gauthier characterized this fiasco as an “unfortunate isolated incident” and said, “Ledger will implement stronger security controls, connecting our build pipeline that implements strict software supply chain security to the NPM distribution channel.”

The Ledger leader’s reference to the NPM distribution channel glosses over the way in which Connect Kit actually gets distributed.

Kalis pointed out that Ledger distributes Connect Kit through a content delivery network (CDN), which means that developers cannot pin the library – limit it to a specific version. Instead, applications that depend on the library always fetch the latest release, which becomes problematic when the latest release has been hijacked.

“Generally speaking, developers protect against supply chain attacks by ‘pinning’ the versions of dependencies that they install,” Kalis said.

Kalis accepted some of the blame by acknowledging that while Ledger should not have published its library in a way that did not support dependency pinning, Revoke.cash should have realized Connect Kit’s distribution method posed a security risk.

However, Kalis isn’t ready to shoulder the burden of compensating those who have lost funds.

“Due to the widespread nature of the exploit, it is impossible to determine which of the victims of the exploit got compromised on Revoke.cash and which got compromised on other websites,” he wrote. “This is why we unfortunately do not see it as a feasible solution for Revoke.cash or other affected websites to directly compensate impacted users.”

Kalis says the only answer as he sees it is for victims to seek reimbursement for losses from Ledger, adding, “It is currently unclear if Ledger plans to do this.”

Ledger, based in France, did not immediately respond to a request for comment. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/12/16/ledger_crypto_conect_kit/

Tags: Hundredstechnologythousands
Previous Post

Ubiquiti blunder let some folks view others’ security cameras, accounts

Next Post

Mayim Bialik Won’t Be Reading Any More (Syndicated) Jeopardy! Clues

Oct. 3 – Ecology fines 35 plastic producers $416,000 for not using enough recycled plastic – Washington State Department of Ecology (.gov)

Ecology Takes Action: 35 Plastic Producers Fined $416,000 for Insufficient Use of Recycled Materials!

May 23, 2025
‘It was probably some kind of an ambush’: 17,000 years ago, a man died in a projectile weapon attack in what is now Italy – Live Science

‘It was probably some kind of an ambush’: 17,000 years ago, a man died in a projectile weapon attack in what is now Italy – Live Science

May 23, 2025
A polymicrobial perspective into the ecological role of Enterococcus faecalis in dental root canal infections – Nature

A polymicrobial perspective into the ecological role of Enterococcus faecalis in dental root canal infections – Nature

May 23, 2025
Trump’s attack on science is growing fiercer and more indiscriminate – The Economist

Trump’s attack on science is growing fiercer and more indiscriminate – The Economist

May 23, 2025
Fit & Fun to raise money for Special Olympics – Coastal Point

Fit & Fun to raise money for Special Olympics – Coastal Point

May 23, 2025
Who took ‘Napalm Girl’? World Press Photo ‘suspends’ attribution of historic Vietnam War image – CNN

Unraveling the Mystery: The Story Behind the Iconic ‘Napalm Girl’ Photograph

May 23, 2025
Javier Milei courts undeclared cash to dollarise Argentina’s economy – Financial Times

Javier Milei courts undeclared cash to dollarise Argentina’s economy – Financial Times

May 23, 2025
SRM Entertainment Announces $5 Million Private Placement – GlobeNewswire

SRM Entertainment Secures $5 Million Investment to Fuel Growth!

May 23, 2025
Seventy-eighth World Health Assembly – Daily update: 22 May 2025 – World Health Organization (WHO)

Highlights from the 78th World Health Assembly: Key Updates for May 22, 2025

May 23, 2025
US indicts Russian accused of running major global cybercrime ring – CNN

US Charges Russian National in Major Global Cybercrime Operation

May 23, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (633)
  • Economy (645)
  • Entertainment (21,558)
  • General (15,227)
  • Health (9,686)
  • Lifestyle (650)
  • News (22,149)
  • People (648)
  • Politics (653)
  • Science (15,869)
  • Sports (21,154)
  • Technology (15,634)
  • World (635)

Recent News

Oct. 3 – Ecology fines 35 plastic producers $416,000 for not using enough recycled plastic – Washington State Department of Ecology (.gov)

Ecology Takes Action: 35 Plastic Producers Fined $416,000 for Insufficient Use of Recycled Materials!

May 23, 2025
‘It was probably some kind of an ambush’: 17,000 years ago, a man died in a projectile weapon attack in what is now Italy – Live Science

‘It was probably some kind of an ambush’: 17,000 years ago, a man died in a projectile weapon attack in what is now Italy – Live Science

May 23, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version