Ledger Connect Kit hack
A December 2023 software supply-chain attack: a phished former Ledger employee's npm key let attackers publish malicious versions of Ledger's widely used 'Connect Kit' library, injecting the Angel Drainer into many dApps. About $500K–$600K was drained in a few hours before a fix shipped.
Also known as: Ledger Connect Kit, Ledger Connect Kit hack, @ledgerhq/connect-kit
Summary
On December 14, 2023, attackers compromised the npm publishing credentials of a former Ledger employee (via phishing) and published malicious versions (1.1.5–1.1.7) of Ledger's "Connect Kit," a JavaScript library used by hundreds of decentralized apps to connect wallets. Because many sites loaded the library from a CDN at runtime, the malicious code propagated automatically. [1][2]
Impact
The injected code carried the Angel Drainer payload, prompting users of affected dApps to sign transactions that drained their wallets; proceeds were split ~85% to the attacker and ~15% to Angel Drainer. Active draining lasted roughly two hours (about five hours total exposure), with losses estimated around $500,000–$600,000 before Ledger shipped a clean version (1.1.8) and coordinated with Tether to freeze some funds. The incident underscored supply-chain risk in widely shared web3 dependencies. [1][2]
Bracketed numbers refer to the numbered sources listed below.
People & entities involved
Sources (2)
See also
- Loci (LOCIcoin)TokensA 2017–2018 ICO for 'LOCIcoin' tied to the InnVenn IP-search platform. The SEC charged Loci and CEO John Wise with fraud for raising $7.6M on false claims about revenue, headcount, and user base; Wise also misused investor funds. Settled with a $7.6M penalty and an officer/director bar.
- Blockchain Terminal (BCT)TokensA 2017–2018 ICO (BCT tokens, ~$30M) for a 'Blockchain Terminal' — a Bloomberg-style crypto trading terminal. The SEC and DOJ said convicted ex-hedge-funder Boaz Manor secretly ran it under a fake identity ('Shaun MacDonald'), using associate Edith Pardo as a front, and lied about the product's adoption.
- Crowd Machine (CMCT)Tokens
This page was last updated on Jun 8, 2026. View revision history.