Ledger Exploit Drained $484K, Upended DeFi; Former Staffer Linked to Malicious Code
Security firm Blockaid's CEO told CoinDesk that users are still at risk.

Hackers stole $484,000 on Thursday after inserting malicious code into the Github library for Connect Kit, a widely-used piece of blockchain software maintained by the crypto wallet firm Ledger. Several major decentralized finance (DeFi) protocols that use the library have been impacted, and users have been warned to avoid using decentralized apps (dApps) altogether until these protocols are updated.
Ledger's Connect Kit is a piece of code that allows DeFi protocols to connect to crypto hardware wallets. The exploit potentially impacts the front-end of all protocols that use the Connect Kit, which include the likes of Sushi, Lido, Metamask and Coinbase.
In an X post on Thursday addressing the incident, Ledger confirmed that an employee had been targeted in a "phishing attack," after which point the attacker "published a malicious version of the Ledger Connect Kit."
Read more: Ledger Exploit Endangers DeFi; Sushi Says 'Do Not Interact With ANY dApps'
A ledger spokesperson told CoinDesk that it has "identified and removed a malicious version of the Ledger Connect Kit," and the company said in its X post that "the window where funds were drained was limited to a period of less than two hours."
FINAL TIMELINE AND UPDATE TO CUSTOMERS:
— Ledger (@Ledger) December 14, 2023
4:49pm CET:
Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.
The investigation continues, here is the timeline of what we know about…
Although Ledger has updated its own code, Ido Ben-Natan, the CEO of blockchain security firm Blockaid told CoinDesk in a Telegram message that "many websites are still affected and users are getting hit." For the risk to be completely mitigated, every protocol using Ledger's Connect Kit has to manually update their version of the library. In the meantime, several protocols remain at risk, specifically revoke.cash, which is a service that is used to remove permissions from DeFi protocols.
"Revoke.cash specifically is affected so don’t interact with it," Ben-Natan added. "the number of impacted funds is hundreds of thousands of dollars over the past two hours."
DeFi-related hacks have been frequent throughout this year, and $303 million was stolen in July alone following exploits to Curve Finance and Multichain. After hacks take place, users typically use websites like revoke.cash to remove permissions from impacted protocols.
In this case, however, as the front-end of websites has been impacted as opposed to hot wallets, revoke.cash users will be prompted to connect their wallets to a malicious token drainer, thus broadening the scope of the hack to anything in a user's wallet.
MetaMask announced that it had deployed a fix to remove the malicious code two hours after the hack occurred.
The nature of the exploit emphasizes the fragile nature of decentralized applications; as protocols use code from several software providers like Ledger, there are numerous points of failure along the supply chain that can ultimately impact users.
Ledger has previously fallen victim to security issues. In 2020 its entire customer database was leaked, leading to fears of sim swapping and home invasion attacks. It also faced controversy this past year after a software update revealed discrepancies between the security of its hardware versus how it was marketed to users.
More For You
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
What to know:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
Standard Chartered says U.S. regional banks most at risk in $500 billion stablecoin shift

The delay of market structure legislation highlights a growing threat to domestic lenders as digital dollars begin to cannibalize traditional bank deposits.
What to know:
- Standard Chartered warned that U.S. regional banks are the most exposed to stablecoin disruption due to their heavy reliance on net interest margin (NIM) for revenue.
- The bank projected that one-third of the growing stablecoin market will be sourced from developed market bank deposits, totaling an estimated $500 billion outflow by 2028.
- A legislative standoff over whether stablecoin providers can pay interest is stalling market structure legislation, though Standard Chartered still expects a March passage.











