Historical retrospective · Security

A compromised library release disrupted crypto front ends

In December 2023 a malicious Ledger Connect Kit package affected some decentralized application interfaces and redirected users toward fraudulent transaction flows.

Event / milestone year: 2023First published

The incident involved a software supply chain dependency used by front ends, not a compromise of every connected blockchain or wallet.

It made third-party JavaScript dependencies a visible part of Web3 security.

Users and developers should verify package provenance and transaction details; a reputable hardware wallet cannot protect against blindly approving a malicious prompt.

Primary source

This retrospective summarizes the source below in original language. The displayed year refers to the dated event, proposal or specification; it is not the article’s publication date. This is not investment, legal or security advice.

Ledger incident notice ↗