Ledger said on December 14, 2023 that attackers had published malicious versions of its Connect Kit, a JavaScript library used by decentralized applications to connect with wallets. The substituted code could present users with malicious transactions and reroute assets if those transactions were signed. Ledger said it had replaced the package with genuine version 1.1.8 and that the incident did not compromise Ledger hardware devices or Ledger Live.
The development mattered beyond one wallet maker. Connect Kit sat inside the software supply chain for third-party decentralized-application interfaces. A poisoned shared dependency could therefore reach users through websites they normally trusted, including users connecting with wallets other than Ledger devices. The incident showed that self-custody hardware could preserve private keys while a separate application layer still induced an owner to authorize a hostile transaction.
What Ledger established on December 14
Ledger Chairman and CEO Pascal Gauthier attributed the publication of the malicious package to a phishing attack against a former employee’s NPMJS account. According to Ledger’s same-day account, the attacker published malicious Connect Kit versions 1.1.5, 1.1.6 and 1.1.7. The code used a rogue WalletConnect project to route funds to an attacker-controlled wallet.
Ledger said its security and technology teams deployed a fix within 40 minutes of becoming aware. It estimated that the malicious file remained live for about five hours, while the period in which funds were actually drained lasted less than two hours. Those durations were company estimates, not independently audited measurements available on December 14. Ledger also said WalletConnect disabled the rogue project and that Tether froze USDT associated with the attacker’s address.
The immediate technical remedy was version 1.1.8. Ledger told developers to verify that version and said direct publishing by the Connect Kit team had been made read-only while publication secrets were rotated. NPM’s package record independently preserves version 1.1.8 in the project’s release history, although the current registry page displays relative publication ages rather than a complete contemporaneous incident log.
Why the blast radius was unusual
Blockaid described the event as a supply-chain attack: instead of first compromising each decentralized application, the attacker altered a dependency those applications loaded. Its incident account said the malicious payload affected the same three versions identified by Ledger and that the patched 1.1.8 package followed on December 14.
The distinction between exposure and loss is important. Loading a compromised front end created the opportunity for the attacker to request a malicious signature; it did not by itself prove that every visitor signed one or lost assets. Likewise, the integrity of Ledger’s hardware was a different question from the safety of transactions displayed by a compromised web interface. Contemporaneous reporting said several applications warned users or temporarily disabled interfaces while the replacement propagated.
Dollar-loss estimates published during December 14 differed as investigators identified addresses, tokens and victims. Coinburn therefore does not present a single loss total as settled event-day fact. Crypto assets also moved across tokens and venues, making a dollar conversion dependent on the address set, valuation timestamp and asset prices selected.
Institutional lesson
The verified development was not a consensus-layer failure or theft of private keys from Ledger devices. It was an identity, offboarding and package-publication failure that reached transaction-signing interfaces. That made the episode institutionally significant: decentralized finance depended on conventional software registries, employee access controls, content delivery and browser code alongside smart contracts and hardware security.
Later documentary context
Ledger’s December 20, 2023 incident report added precise Central European Time entries and said the former employee’s NPM access had not been revoked. It also identified the malware as Angel Drainer. Those details are later findings, not claims treated as established in the December 14 event-day record.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

