Ledger Responds to Connect Kit Exploit With Reimbursement Plan, Security Overhaul

Share This Post

Ledger Responds to Connect Kit Exploit With Reimbursement Plan, Security Overhaul

In a decisive move following a significant security incident, Ledger, a well known crypto hardware wallet manufacturer and security firm, announced a response plan. Approximately $600,000 in assets were stolen from users due to an exploit involving blind signing on EVM decentralized applications (dapps). Ledger detailed on Dec. 20, 2023, that it has vowed to fully reimburse all affected users, including non-customers, a commitment underscored by the company’s CEO, Pascal Gauthier.

Crypto Security Firm Ledger Vows Full Payback Post $600K Hack

The incident, detected on December 14, 2023, involved an exploit of the Ledger Connect Kit, which led to the injection of malicious code into various dapps. This code deceived users into signing transactions that drained their wallets. Ledger’s detection and the crypto community’s response led to several alerts, though the attack resulted in the loss of around $600k in user assets.

The company said on the social media platform X that it is not only addressing the immediate repercussions of the attack but also taking steps to prevent future incidents. By June 2024, Ledger devices will no longer support blind signing, shifting to a more secure method known as Clear Signing. This method will enable users to verify all transaction details on their Ledger devices before signing, enhancing security significantly.

As part of its remedial actions, Ledger detailed that it has been meticulously reviewing and auditing all their access controls. They are reinforcing policies around code review, deployment, distribution, and access control. This includes integrating external tools into their maintenance and offboarding checks and conducting regular internal audits to ensure effective implementation.

Additionally, Ledger further explained that it is intensifying its focus on security training for employees. The company already conducts security training sessions, including phishing training, and plans to reinforce this program in early 2024. The X announcement also said that Ledger is also prioritizing regular third-party security assessments, with a specific audit focused on access control, code promotion, and distribution slated for early next year.

The company announced on X that it created an active outreach for impacted users, working through specifics with them to ensure full reimbursement of their stolen crypto assets. This gesture of reimbursement is expected to be completed by the end of February 2024. Lastly, the company has urged dapp developers to support the Clear Signing security feature, highlighting the need for collaboration across the ecosystem to enhance user protection.

What do you think about Ledger addressing the recent exploit and reimbursing victims? Share your thoughts and opinions about this subject in the comments section below.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Aave Address Count On Optimism Rapidly Growing, Will Price Rise To New 13-Month High?

Aave, the decentralized lending platform, is among the largest DeFi protocols by total value locked (TVL) Over the years, despite the crypto price boom and bust cycle, the platform has operated

The rise of crypto neobanks: Nikolai Denisenko on Brighty’s mission

In a recent episode of the SlateCast, Nikolay Denisenko, Co-Founder and CTO of Brighty App, joined CryptoSlate‘s Senior Editor Liam “Akiba” Wright and CEO Nate Whitehill to

Bitcoin Closes in on Price Peak – $69K Resistance in Sight

On Friday, bitcoin reached its highest price since late July, coming within just $2 of breaking through the $69,000 mark Recent data shows the cryptocurrency market has been on a consistent upward

BlackRock eyes crypto derivatives market with BUIDL as collateral

BlackRock is reportedly in discussions with several centralized exchanges to allow its BUIDL fund to be used as collateral for derivatives trades As reported by Bloomberg on Oct 18, people familiar

Before Bitcoin: 4 Early Digital Currencies and Why They Collapsed

Before bitcoin took the spotlight, several digital currencies aimed to change the way we exchange value, but none could withstand the test of time Ecash, E-gold, Liberty Reserve, and Q coins each had

Crypto Craze: Investor Nets A 3,360% Gain, Turning $86,000 Into $3.75 Million

In another fabulous story from the crypto market, an investor has realized a staggering 3,360% return, transforming an initial investment of $86,000 into approximately $39 million This extraordinary