24/7 Cryptocurrency News

Rug Pull Alert: Multiple Protocols Affected in Ledger ConnectKit Attack

Major rug pull scare emerges as the ConnectKit Library is facing a major vulnerability that is affecting multiple protocols
Published by
Rug Pull Alert: Multiple Protocols Affected in Ledger ConnectKit Attack

In a recent and alarming development, the Decentralized Finance (DeFi) space faced a rug-pull security breach with a supply chain attack on the Ledger ConnectKit.

Advertisement

The Ledger ConnectKit Attack Unveiled

The vulnerability, now labeled a “supply chain attack,” poses a serious risk to users and their assets, potentially allowing malicious code injection into various Decentralized Applications (dApps). The compromised package identified in the attack is LedgerHQ’s ConnectKit, specifically versions greater than 1.1.4, according to Web3 security firm, Blockaid.

The impact of the supply chain attack on Ledger ConnectKit was felt across various DeFi protocols. Blockaid mentioned that SushiSwap, Kyber, RevokeCash, and Zapper were among the vulnerable decentralized exchanges

Reacting promptly to the threat, Kyber and RevokeCash disabled their front ends. It is worth noting that this vulnerability comes only shortly after KyberSwap fell victim to a major exploit that resulted in the loss of around $46 million in various cryptocurrencies. 

Blockaid estimates that approximately $150,000 has been lost within just a few hours, emphasizing the immediate and widespread impact of the attack. The security firm was quick to assure users of Blockaid-enabled wallets that they are protected from this specific threat, but the broader implications of this attack could pose substantial risks to the broader Web3 ecosystem.

The origin of the vulnerability traces back to the use of a specific Content Delivery Network (CDN) to host the Ledger ConnectKit software library. Matthew Lilly, the Chief Technology Officer of Sushi, explained, 

“LedgerHQ/connect-kit loads JS from a CDN, their CDN account has been compromised which is injecting malicious JS into multiple dApps.”

Advertisement

Ledger Unveils Response and Recovery Efforts

In response to the attack, Ledger issued a statement acknowledging the compromise and assuring users that a genuine version of the Ledger ConnectKit is being pushed to replace the malicious file. A software patch has also been developed to address the vulnerability.

As a precautionary measure, users are strongly advised to refrain from interacting with any dApps associated with the Ledger ConnectKit until further notice. The incident highlights the importance of continuous security audits, proactive measures, and swift responses to emerging threats to safeguard the integrity of decentralized financial systems. 

Advertisement

Share
Godfrey Benjamin

Benjamin Godfrey is a blockchain enthusiast and journalists who relish writing about the real life applications of blockchain technology and innovations to drive general acceptance and worldwide integration of the emerging technology. His desires to educate people about cryptocurrencies inspires his contributions to renowned blockchain based media and sites. Benjamin Godfrey is a lover of sports and agriculture. Follow him on X, Linkedin

Published by
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Recent Posts

  • Bitcoin News

Michael Saylor Predicts Bitcoin Will Outperform S&P 500 Forever

Billionaire Michael Saylor has once again made a bold claim about Bitcoin’s (BTC) future. He…

September 20, 2025
  • 24/7 Cryptocurrency News

Crypto Market Eyes Upside as FTX Set to Repay $1.6B to Customers

The estate of the defunct crypto exchange FTX has revealed plans to distribute billions of…

September 20, 2025
  • 24/7 Cryptocurrency News

Elon Musk’s X Vows Crackdown on Bribery Network Behind Crypto Scam Accounts

X has vowed a strict crackdown after exposing a bribery network tied to crypto scam…

September 20, 2025
  • 24/7 Cryptocurrency News

Flare Unveils First XRP-Backed Stablecoin, Boosting XRP’s Utility

According to Flare Network, there’s now a stablecoin backed with XRP running on Enosys Liquity…

September 19, 2025
  • 24/7 Cryptocurrency News

MLP Bets Big on Climate Change: Favours Play-To-Impact, Over Play-To-Earn

Amidst increasing criticism of the popular play-to-earn model due to its unsustainability, a new chapter…

September 19, 2025
  • 24/7 Cryptocurrency News

MetaMask to Integrate Hyperliquid’s Perpetuals In-Wallet Following mUSD Launch

Crypto wallet MetaMask looks set to integrate Hyperliquid's perpetuals trading on its platform. This development…

September 19, 2025