Another chapter in the history of hacking was added today with the hack of the Ledger cold wallet that sweeped assets worth $484k.
The Chronicle of the Hack
The hacker gained access to the NPMJS account of a former Ledger employee by making him a victim of phishing. There, the attacker published a malicious version of the Ledger Connect kit (affecting versions 1.1.5, 1.1.6, and 1.1.7) and obtained funds for his wallet using the WalletConnect project.
Ledger in Action
Ledger immediately swung into action with the help of revelant parties. WalletConnect disabled the rogue project, Chainalysis identified the wallet, and Tether frozen the USDTs of that wallet. Ledger replaced the affected version and prevented the connect-kit developers from pushing the package on the NPM project.
Ledger is Suspect too?
Hot wallets like Atomic wallet, Metamask and Exudos are still blamed for security flaws, but cold wallets like ledgers are bringing up much worse matters. Ledger's blame to "former employee" is not acceptable, but if former employee still have publishing acess, then it is much worse for Ledger. Hardware wallet market might get a competitor less.