Historical retrospective · Security
A compromised library release disrupted crypto front ends
In December 2023 a malicious Ledger Connect Kit package affected some decentralized application interfaces and redirected users toward fraudulent transaction flows.
The incident involved a software supply chain dependency used by front ends, not a compromise of every connected blockchain or wallet.
It made third-party JavaScript dependencies a visible part of Web3 security.
Users and developers should verify package provenance and transaction details; a reputable hardware wallet cannot protect against blindly approving a malicious prompt.
Primary source
This retrospective summarizes the source below in original language. The displayed year refers to the dated event, proposal or specification; it is not the article’s publication date. This is not investment, legal or security advice.