News: 1702685604

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned

(2023/12/16)


Cryptocurrency wallet maker Ledger says someone slipped malicious code into one of its JavaScript libraries to steal more than half a million dollars from victims.

The library in question is Connect Kit, which allows DApps – decentralized software applications – to connect to and use people's Ledger hardware wallets.

Pascal Gauthier, CEO of Ledger, in a [1]public post said a former employee had been duped by a phishing attack, which allowed an unauthorized party to upload a malicious file to the company's NPM registry account.

[2]

"The attacker published a malicious version of the [3]Ledger Connect Kit (affecting versions 1.1.5, 1.1.6, and 1.1.7)," said Gauthier. "The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet."

[4]

[5]

The [6]malicious file was what's known as a " [7]crypto drainer " – it siphons funds from digital wallets. And because [8]dozens of crypto projects utilize the Connect Kit library, the potential financial loss could have been considerable. The damage however was limited because the compromised file was only live for about five hours and active [9]for about two .

During this period, it's [10]claimed that the attacker managed to obtain more than $610,000 worth of crypto tokens. Revoke.cash, a service for revoking certain crypto transactions – which was affected by the incident – reports losses on the order of [11]$850,000 .

[12]

According to Gauthier, the attack was addressed within 40 minutes of discovery, the attacker's blockchain address has been identified, and Tether has frozen the attacker's Tether tokens. Authorities, he claims, have been notified.

"The authentic and verified version of the Ledger Connect Kit, version 1.1.8, is now in circulation and safe to use," said Gauthier.

"Safe" may be overstating the case: According to security firm Socket, which provides algorithmic assessments of NPM packages, Connect Kit currently rates 51 out of 100 for Supply Chain Security and 55 out of 100 for Quality.

[13]Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes

[14]Interpol moves against human traffickers who enslave people to scam you online

[15]Crypto crasher Do Kwon's extradition approved, but destination is unclear

[16]48-nation bloc to crack down on using crypto assets to avoid tax

Gauthier insists standard practice at Ledger is that no one person can deploy code without a multiparty review.

"We have strong access controls, internal reviews, and multi-signature code when it comes to most parts of our development," he said. "This is the case in 99 percent of our internal systems. Any employee who leaves the company has their access revoked from every Ledger system."

[17]

And yet Ledger's account of the incident – a former employee surrendered credentials to a phishing scheme, allowing a miscreant to gain access to Ledger's NPM account to push through bad code – suggests this was one occasion where company security controls fell short.

According to Rosco Kalis, a software engineer for Revoke.cash, Ledger did not have [18]two-factor authentication in place for NPM, which presumably would have prevented the phishing attack from working. What's more, Kalis [19]claimed Ledger failed to revoke code publication rights for its former employee.

Gauthier characterized this fiasco as an "unfortunate isolated incident" and said, "Ledger will implement stronger security controls, connecting our build pipeline that implements strict software supply chain security to the NPM distribution channel."

The Ledger leader's reference to the NPM distribution channel glosses over the way in which Connect Kit actually gets distributed.

Kalis pointed out that Ledger distributes Connect Kit through a content delivery network (CDN), which means that developers cannot pin the library – limit it to a specific version. Instead, applications that depend on the library always fetch the latest release, which becomes problematic when the latest release has been hijacked.

"Generally speaking, developers protect against supply chain attacks by 'pinning' the versions of dependencies that they install," Kalis said.

Kalis accepted some of the blame by acknowledging that while Ledger should not have published its library in a way that did not support dependency pinning, Revoke.cash should have realized Connect Kit's distribution method posed a security risk.

However, Kalis isn't ready to shoulder the burden of compensating those who have lost funds.

"Due to the widespread nature of the exploit, it is impossible to determine which of the victims of the exploit got compromised on Revoke.cash and which got compromised on other websites," he wrote. "This is why we unfortunately do not see it as a feasible solution for Revoke.cash or other affected websites to directly compensate impacted users."

Kalis says the only answer as he sees it is for victims to seek reimbursement for losses from Ledger, adding, "It is currently unclear if Ledger plans to do this."

Ledger, based in France, did not immediately respond to a request for comment. ®

Get our [20]Tech Resources



[1] https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZX0u9mW47fMNOW@9pnTlagAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.npmjs.com/package/@ledgerhq/connect-kit?activeTab=versions

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZX0u9mW47fMNOW@9pnTlagAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZX0u9mW47fMNOW@9pnTlagAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://cdn.jsdelivr.net/npm/2e6d5f64604be31/2e6d5f64604be31.js

[7] https://blog.confiant.com/how-one-crypto-drainer-template-facilitates-tens-of-millions-of-dollars-in-theft-66f3794aea4b

[8] https://sourcegraph.com/search?q=context:global+@ledgerhq/connect-kit&patternType=standard&sm=1&groupBy=repo

[9] https://x.com/Ledger/status/1735326240658100414

[10] https://x.com/zachxbt/status/1735292040986886648

[11] https://revoke.cash/exploits/ledger-connect-kit?chainId=1

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZX0u9mW47fMNOW@9pnTlagAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/12/14/moneygrubbing_crooks_abuse_oauth_apps/

[14] https://www.theregister.com/2023/12/12/interpol_cyberscam_trafficker_action/

[15] https://www.theregister.com/2023/11/27/do_kwon_extradition_approved/

[16] https://www.theregister.com/2023/11/13/carf_2027_adoption_set/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZX0u9mW47fMNOW@9pnTlagAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://docs.npmjs.com/configuring-two-factor-authentication

[19] https://revoke.cash/blog/2023/ledger-connect-kit-hack-retrospective

[20] https://whitepapers.theregister.com/



Dog bites man, water is wet, cryptocurrency operation is "hacked"

David 132

Crypto "investors" got hacked and lost money?

Oh no!

Anyway. Here's James with news about the Dacia Sandero.

Re: Dog bites man, water is wet, cryptocurrency operation is "hacked"

David 132

Ha, found the butthurt crypto investor.

Somethings very phishie

Snowy

Pascal Gauthier, CEO of Ledger, in a public post said a former employee had been duped by a phishing attack, which allowed an unauthorized party to upload a malicious file to the company's NPM registry account.

Is a brown envelop full of money considered to be a phishing attack now?

Re: Somethings very phishie

Snowy

Someone not seeing the joke?

Re: Somethings very phishie

Throatwarbler Mangrove

Butthurt crypto bro.

I'm sorry, what was that?

MachDiamond

How exactly (in excruciating detail) is crypto better than cash? I am, of course, talking about transactions not involving any sort of contra-ban or bribery. I have money in a bank account insured by a government agency. I have precious metals and some gems. I have some art and I have banknotes. I don't have a penchant for drugs, firearms or have enough money for a down payment on a honest politician (one that stays bought). I suppose that the fees could be less painful when trying to take money across borders in large amounts, but I've done that before in creative ways aside from a suitcase full of cash.

Many people seem to be rushing into crypto under the impression that it will be an easy way to make a pile of easy money. Easy is the operative word. The truth is that the bottom levels of the pyramid where money can be made have already been filled up and those above that point are taking a huge risk somebody can be found willing to give them more per coin before the music stops and it's discovered that there are far fewer chairs than one was lead to believe.

It's at the point where the aren't many common expenses that aren't already exposed to government prying. Rents, mortgages, utilities, insurance, loan payments are all either keep track of through registration, licensing and taxes or easily subpoenaed. What's left are actually the important things that can be paid with cash that will say more about you than you own a car and live in a home.

HELP! Man trapped in a human body!