Ledger to reimburse victims of the Connect Kit exploit

Ledger to reimburse victims of the Connect Kit exploit
фото показано с : invezz.com

2023-12-21 18:04

Crypto hardware wallet maker Ledger plans to reimburse all users who lost funds in the recent Ledger Connect Kit exploit, according to an update the company published today.

Ledger’s pledge, shared with the public via its official X account, noted that this refund program will be extended to all victims of the exploit – including those not customers of Ledger.

A total of $600,000 was stolen during the December 14, 2023 attack on EVM dApps using the Ledger connect library.

We are 100% focused on following up to last week’s security incident, making sure incidents like this are prevented in the future, and that the ecosystem remains safe.

We are aware of approximately $600k in assets impacted, stolen from users blind signing on EVM DApps.

Ledger…

— Ledger (@Ledger) December 20, 2023 Reimbursement to be done by February 2024

A security incident report Ledger published on December 20 says the Connect Kit exploit had injected malicious code dApps. Users were tricked into signing transactions, allowing the attacker to drain their wallets. Although Ledger quickly detected the incident, a number of users had already fallen victim.

“Ledger will make sure victims affected will be made whole, and are committing to work with the DApp ecosystem to allow Clear Signing, and no longer allow Blind Signing with Ledger devices by June 2024,” the company noted via its official X account.

The commitment follows an earlier pledge by Ledger CEO & Chairman Pascal Gauthier that the hardware wallet maker will ensure all victims are made whole. Today’s announcement reaffirmed this:

“We commit, by any way possible, including gestures of goodwill, to make sure this is done by the end of February, 2024. We are already in contact with many impacted users and are actively working through the specifics with them.”

While users have been asked to revoke transactions authorised to affected dApps as part of “best security practices,” the company is looking to collaborate with developers and other industry players to support Clear Signing.

As opposed to Blind Signing, Clear Signing allows users to verify every transaction on their device. Ledger says it will end Blind Sign on its devices by June 2024.

The company has also assured users that its hardware devices and Ledger Live “were not made vulnerable by this exploit.

The post Ledger to reimburse victims of the Connect Kit exploit appeared first on Invezz

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Quantum Resistant Ledger (QRL) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.307
Капитализация $0 Rank 99999
Цена в час новости $ 0.1091 (-100%)

ledger exploit all reimburse kit victims connect

ledger exploit → Результатов: 18


Фото:

Ledger Patches Nano X Supply Chain Vulnerability

The Ledger security team has patched a hardware exploit that could compromise Ledger Nano X wallets as a part of a supply chain attack. Following a report from Kraken Security Labs, a cybersecurity division of Kraken, that showed that the Ledger hardware wallet was susceptible to a supply chain attack, the device manufacturer has announced […] The post Ledger Patches Nano X Supply Chain Vulnerability appeared first on BeInCrypto.

2020-7-9 12:12


Фото:

Security Researchers Reveal Wallet Vulnerabilities On Stage at 35C3

In a demonstration titled “Wallet. fail,” a team of security researchers hacked into the Trezor One, Ledger Blue and Ledger Nano S. Unfortunately, it appears as if their findings were first put on display at the 35th Chaos Communication Congress (35C3) in Leipzig, Germany, rather than through accepted Responsible Disclosure practices, which would have allowed the manufacturers to patch the vulnerabilities and protect their customers from any potential attack.

2019-1-1 19:15