Share this article

Ledger Exploit Endangers DeFi; Sushi Says 'Do Not Interact With ANY dApps'

The exploit reportedly prompts users to connect their wallets via a pop-up, triggering a token drainer.

Updated Mar 9, 2024, 2:16 a.m. Published Dec 14, 2023, 12:48 p.m.
jwp-player-placeholder

Sushi's Chief Technology Officer warned of an industry-wide exploit related to a Ledger's Connect Kit as the decentralized finance (DeFi) protocol was hit by a front-end exploit.

Ledger, a maker of hardware wallets, provides Connect Kit software that decentralized finance protocols such as Lido, Metamask and Coinbase, along with Sushi, use to connect decentralized applications (dapps) to its products. By compromising the front end of a website or application, hackers can alter functions users see and con them into inadvertently sending cash to the exploiters rather than their own wallets.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

“Do not interact with ANY dApps until further notice,” Sushi CTO Matthew Lilley wrote on X. “It appears that a commonly used web3 connector has been compromised, which allows for injection of malicious code affecting numerous dApps.”

Read more: Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code

The exploit reportedly prompts users to connect their wallets via a pop-up, which then triggers the token drainer. Issues have also been reported across other DeFi websites, including Zapper and RevokeCash.

Five hours after the hack, Ledger published a post-mortem on X. It confirmed that a former Ledger employee fell victim to a phishing attack, which allowed a hacker to insert malicious code into Ledger's Connect Kit. It adds that the code has now been removed and stablecoin issuer Tether has frozen the hacker's wallet.

"We've identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps," Sushi wrote in a statement. "If you have the Sushi page open and see an unexpected 'Connect Wallet' pop-up, DO NOT interact or connect your wallet."

One X user pointed out that Ledger’s library had been compromised and replaced with a token drainer.

Ledger said it had "identified and removed a malicious version of the Ledger Connect Kit."

"A genuine version is being pushed to replace the malicious file now," Ledger said. "Do not interact with any dApps for the moment. We will keep you informed as the situation evolves. Your Ledger device and Ledger Live were not compromised."

UPDATE (Dec. 14, 13:23 UTC): Adds context throughout.

UPDATE (Dec. 14, 14:49 UTC): Adds statement from Ledger.

UPDATE (Dec. 14, 15:00 UTC): Rewrites headline; changes lead photo.

UPDATE (Dec. 14, 15:58 UTC): Adds statement from Ledger.

Mais para você

Protocol Research: GoPlus Security

GP Basic Image

O que saber:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

Mais para você

French Banking Giant BPCE to Roll Out Crypto Trading for 2M Retail Clients

(CoinDesk)

The service will allow customers to buy and sell BTC, ETH, SOL, and USDC through a separate digital asset account managed by Hexarq.

O que saber:

  • French banking group BPCE will start offering crypto trading services to 2 million retail customers through its Banque Populaire and Caisse d’Épargne apps, with plans to expand to 12 million customers by 2026.
  • The service will allow customers to buy and sell BTC, ETH, SOL, and USDC through a separate digital asset account managed by Hexarq, with a €2.99 monthly fee and 1.5% transaction commission.
  • The move follows similar initiatives by other European banks, such as BBVA, Santander, and Raiffeisen Bank, which have already started offering crypto trading services to their customers.