Ledger Exploit Endangers DeFi; Sushi Says 'Do Not Interact With ANY dApps'
The exploit reportedly prompts users to connect their wallets via a pop-up, triggering a token drainer.
Sushi's Chief Technology Officer warned of an industry-wide exploit related to a Ledger's Connect Kit as the decentralized finance (DeFi) protocol was hit by a front-end exploit.
Ledger, a maker of hardware wallets, provides Connect Kit software that decentralized finance protocols such as Lido, Metamask and Coinbase, along with Sushi, use to connect decentralized applications (dapps) to its products. By compromising the front end of a website or application, hackers can alter functions users see and con them into inadvertently sending cash to the exploiters rather than their own wallets.
“Do not interact with ANY dApps until further notice,” Sushi CTO Matthew Lilley wrote on X. “It appears that a commonly used web3 connector has been compromised, which allows for injection of malicious code affecting numerous dApps.”
Read more: Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code
The exploit reportedly prompts users to connect their wallets via a pop-up, which then triggers the token drainer. Issues have also been reported across other DeFi websites, including Zapper and RevokeCash.
Five hours after the hack, Ledger published a post-mortem on X. It confirmed that a former Ledger employee fell victim to a phishing attack, which allowed a hacker to insert malicious code into Ledger's Connect Kit. It adds that the code has now been removed and stablecoin issuer Tether has frozen the hacker's wallet.
FINAL TIMELINE AND UPDATE TO CUSTOMERS:
— Ledger (@Ledger) December 14, 2023
4:49pm CET:
Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.
The investigation continues, here is the timeline of what we know about…
"We've identified a critical issue the ledger connector has been compromised, potentially allowing the injection of malicious code affecting various dApps," Sushi wrote in a statement. "If you have the Sushi page open and see an unexpected 'Connect Wallet' pop-up, DO NOT interact or connect your wallet."
One X user pointed out that Ledger’s library had been compromised and replaced with a token drainer.
Ledger said it had "identified and removed a malicious version of the Ledger Connect Kit."
"A genuine version is being pushed to replace the malicious file now," Ledger said. "Do not interact with any dApps for the moment. We will keep you informed as the situation evolves. Your Ledger device and Ledger Live were not compromised."
UPDATE (Dec. 14, 13:23 UTC): Adds context throughout.
UPDATE (Dec. 14, 14:49 UTC): Adds statement from Ledger.
UPDATE (Dec. 14, 15:00 UTC): Rewrites headline; changes lead photo.
UPDATE (Dec. 14, 15:58 UTC): Adds statement from Ledger.
Sizin için daha fazlası
KuCoin Hits Record Market Share as 2025 Volumes Outpace Crypto Market

KuCoin captured a record share of centralised exchange volume in 2025, with more than $1.25tn traded as its volumes grew faster than the wider crypto market.
Bilinmesi gerekenler:
- KuCoin recorded over $1.25 trillion in total trading volume in 2025, equivalent to an average of roughly $114 billion per month, marking its strongest year on record.
- This performance translated into an all-time high share of centralised exchange volume, as KuCoin’s activity expanded faster than aggregate CEX volumes, which slowed during periods of lower market volatility.
- Spot and derivatives volumes were evenly split, each exceeding $500 billion for the year, signalling broad-based usage rather than reliance on a single product line.
- Altcoins accounted for the majority of trading activity, reinforcing KuCoin’s role as a primary liquidity venue beyond BTC and ETH at a time when majors saw more muted turnover.
- Even as overall crypto volumes softened mid-year, KuCoin maintained elevated baseline activity, indicating structurally higher user engagement rather than short-lived volume spikes.
More For You
Coinbase CEO says Big banks now view crypto as an ‘existential’ threat to their business

Brian Armstrong returns from World Economic Forum with message: traditional finance is taking crypto seriously
What to know:
- Coinbase CEO Brian Armstrong said a top executive at one of the world’s 10 largest banks told him crypto is now the bank’s “number one priority” and an “existential” issue.
- At Davos, Armstrong highlighted tokenization of assets and stablecoins as major themes, arguing they could broaden access to investments for billions while threatening to bypass traditional banks.
- He described the Trump administration as the most crypto-forward government globally, backing efforts like the CLARITY Act, and predicted that AI agents will increasingly use stablecoins for payments outside conventional banking rails.












