Ledger Responds to Connect Kit Exploit With Reimbursement Plan, Security Overhaul

Share This Post

Ledger Responds to Connect Kit Exploit With Reimbursement Plan, Security Overhaul

In a decisive move following a significant security incident, Ledger, a well known crypto hardware wallet manufacturer and security firm, announced a response plan. Approximately $600,000 in assets were stolen from users due to an exploit involving blind signing on EVM decentralized applications (dapps). Ledger detailed on Dec. 20, 2023, that it has vowed to fully reimburse all affected users, including non-customers, a commitment underscored by the company’s CEO, Pascal Gauthier.

Crypto Security Firm Ledger Vows Full Payback Post $600K Hack

The incident, detected on December 14, 2023, involved an exploit of the Ledger Connect Kit, which led to the injection of malicious code into various dapps. This code deceived users into signing transactions that drained their wallets. Ledger’s detection and the crypto community’s response led to several alerts, though the attack resulted in the loss of around $600k in user assets.

The company said on the social media platform X that it is not only addressing the immediate repercussions of the attack but also taking steps to prevent future incidents. By June 2024, Ledger devices will no longer support blind signing, shifting to a more secure method known as Clear Signing. This method will enable users to verify all transaction details on their Ledger devices before signing, enhancing security significantly.

As part of its remedial actions, Ledger detailed that it has been meticulously reviewing and auditing all their access controls. They are reinforcing policies around code review, deployment, distribution, and access control. This includes integrating external tools into their maintenance and offboarding checks and conducting regular internal audits to ensure effective implementation.

Additionally, Ledger further explained that it is intensifying its focus on security training for employees. The company already conducts security training sessions, including phishing training, and plans to reinforce this program in early 2024. The X announcement also said that Ledger is also prioritizing regular third-party security assessments, with a specific audit focused on access control, code promotion, and distribution slated for early next year.

The company announced on X that it created an active outreach for impacted users, working through specifics with them to ensure full reimbursement of their stolen crypto assets. This gesture of reimbursement is expected to be completed by the end of February 2024. Lastly, the company has urged dapp developers to support the Clear Signing security feature, highlighting the need for collaboration across the ecosystem to enhance user protection.

What do you think about Ledger addressing the recent exploit and reimbursing victims? Share your thoughts and opinions about this subject in the comments section below.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Solana Aims for $190 Mark, Here’s What Traders Should Watch

The post Solana Aims for $190 Mark, Here’s What Traders Should Watch appeared first on Coinpedia Fintech News Solana (SOL), the world’s fifth-biggest cryptocurrency by market cap, is poised for a

Bitcoin Staking Protocol Solv Integrates Liquid BTC With Solana’s Defi Ecosystem

The Solv Protocol has announced the integration of Liquid Bitcoin (LST) into Solana’s decentralized finance (Defi) ecosystem through its new product, SolvbtcJUP This initiative allows Bitcoin

Ethereum Bullish Pattern Signals Upcoming Rally – Analyst Sets $2,870 Target

All eyes are on Ethereum as the crypto market watches closely following Bitcoin’s recent surge Analysts and investors are now cautiously waiting for Ethereum to catch up, with some fearing that

Fed official touts DeFi as ally, not rival, to traditional finance

Federal Reserve Governor Christopher Waller believes that DeFi is more likely to work alongside traditional finance rather than replace it entirely Speaking at the Vienna Macroeconomics Workshop on

Revolution in Your Pocket: Why the Ethereum Phone Challenges Corporate Control

Freedom Factory has launched Dgen1, dubbed the “Ethereum Phone,” a mobile device integrating Ethereum’s ethOS v40 operating system for seamless crypto interactions Freedom

Tokenization and Stablecoins Close to Being Regulated in This Latam Giant

The President of the Central Bank of the Latin American giant announced plans to expedite the regulation of asset tokenization and stablecoins by 2025 The bank will issue a new consultation this