News

Ledger CEO on Hacking Incident, “The Threat Has Passed”

Ledger CEO, Pascal Gauthier has sent a message of hope to the community confirming that the hacking threat has now passed away
Published by
Ledger CEO on Hacking Incident, “The Threat Has Passed”

In light of the recent Ledger Hacking, the Decentralized Finance (DeFi) protocol’s Chairman and CEO, Pascal Gauthier has issued a new update.

Advertisement

Ledger Hacking Acknowledged and Explained

He started by acknowledging the recent exploit which involved the injection of malicious code into the Javascript library. It affected mostly versions greater than 1.1.4, that is, versions 1.1.5, 1.1.6, and 1.1.7.  Furthermore, he explained that the hack was as a result of a loophole exploited by the bad actor. 

A former employee fell victim to a phishing attack that eventually provided a bad actor with access to upload a malicious file to Ledger’s NPMJS. This NPMJS is a package manager for Javascript code shared between apps. Ledger swung into action immediately to salvage the situation with support from WalletConnect, its partner. At once, the NPMJS was removed and the malicious file was immediately disabled.

All these happened within forty minutes of the exploit’s discovery. Gauthier highlighted the alliance as a good reference of the industry working swiftly together to tackle security challenges that plagues the ecosystem. 

Advertisement

Hacker Exploit Scare is Over

Ordinarily, no single person has the sole power to deploy codes on Ledger’s ConnectKit as he would require that some other parties review the transaction. At the same time, Gauthier clarified that every employee who leaves the company at any time and for whatever reasons, always has their access to the Ledger systems revoked at once. 

Prior to exiting the company, employees are granted access to controls, internal reviews, and multi-signature code especially, as it has to do with most parts of Ledger’s development. This is prevalent in 90% of the firm’s development. Gauthier suggested that the DeFi protocol had previously imbibed security strategies to protect investors. 

However, the latest attack is a clear proof and reminder that security is not static. Therefore, “Ledger must continuously improve our security systems and processes. In this area, Ledger will implement stronger security controls, connecting our build pipeline that implements strict software supply chain security to the NPM distribution channel.”

A new version of the Ledger Connect Kit has been introduced and users who intend to keep utilizing the tool, are advised to upgrade to this version. Once Ledger Connect Kit version 1.1.8 is installed, users may have to wait for up to 24 hours before activating. So far, it’s looking good plus Gauthier has assured users that the situation is now under control and “the threat has passed.”

Advertisement

Share
Godfrey Benjamin

Benjamin Godfrey is a blockchain enthusiast and journalists who relish writing about the real life applications of blockchain technology and innovations to drive general acceptance and worldwide integration of the emerging technology. His desires to educate people about cryptocurrencies inspires his contributions to renowned blockchain based media and sites. Benjamin Godfrey is a lover of sports and agriculture. Follow him on X, Linkedin

Published by
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Recent Posts

  • News

Will Bitcoin Rally as JPMorgan Tips Fed To End QT at FOMC Meeting?

Bitcoin traders are turning their attention to this week’s Federal Open Market Committee (FOMC) meeting.…

October 26, 2025
  • News

White House Crypto Czar Backs Michael Selig as ‘Excellent Choice’ To Lead CFTC

White House crypto czar David Sacks has shown his support for Donald Trump's nomination of…

October 25, 2025
  • News

Ripple Explores New XRP Use Cases as Brad Garlinghouse Reaffirms Token’s ‘Central’ Role

Crypto firm Ripple has revealed that it is exploring new ways to use XRP within…

October 25, 2025
  • News

Kyrgyzstan Adds Binance Coin (BNB) to National Crypto Reserve, CZ Confirms

Kyrgyzstan has made a significant move in the adoption of digital finance. It has now…

October 25, 2025
  • News

Ripple-Backed Evernorth Grows XRP Treasury to $1B Ahead of Nasdaq Listing

Ripple-backed Evernorth's XRP treasury has grown to $1 billion just days after the company announced…

October 25, 2025
  • News

Trump Tariff Tensions Ease as U.S. and China Hold Positive Trade Talks Ahead of Oct 30 Summit

In fresh developments, the United States and China’s trade teams have commenced negotiations on the…

October 25, 2025