How the Ledger Connect Kit was poisoned: a former employee's account nobody closed
Ledger is best known for hardware wallets built to keep crypto safe, and those devices were never touched in this attack. Instead, attackers used the old software publishing account of someone who no longer worked there.[1][2] This case file covers what happened on December 14, 2023, how a leftover login let bad code spread to crypto websites, what it cost, and the control that was missing.
What happened
Ledger publishes a small piece of code called Connect Kit. Other crypto websites, often called dApps, load it so their visitors can connect a wallet. Because many sites pull in the latest version automatically, whoever can publish Connect Kit can change what runs on all of them at once.
On the morning of December 14, 2023, a former Ledger employee was hit by a phishing attack aimed at their account on npm, the public registry where developers publish JavaScript code. Ledger said the attackers got around the account's 2-step login by stealing an active session.[1] That account still had permission to publish Connect Kit.
Between 9:49 and 11:37 a.m. Central European Time, the attackers published 3 poisoned versions of Connect Kit.[1][2] For anyone visiting an affected site, the code could show fake transaction requests that, if approved, sent tokens and NFTs to wallets controlled by the attackers.[1]
How they got in
Ledger's own incident report is plain about the root cause. When the employee left, their access to Ledger's internal systems was revoked automatically. But their access to npm, an outside service, had to be removed by hand, and it was not.[1] Ledger noted that many outside tools cannot be shut off through a company's normal automated offboarding.[1]
So the chain was short. A person who no longer worked there still held the keys to publish a widely used piece of Ledger code. A phishing attack took those keys. The poisoned code then flowed into every website that trusted Connect Kit to update itself. The malicious code used a rogue project on WalletConnect, a common wallet-connection service, to route stolen funds.[2]
How it was caught
Ledger learned of the attack at 1:45 p.m. CET, when partners in the crypto security community raised the alarm. Its team shipped a clean version at 2:18 p.m., about 40 minutes later.[1] Because copies of the bad code were cached on content delivery networks, the servers that speed up websites, it took about 5 hours in total to fully clear, though Ledger estimated the window for active theft was under 2 hours.[1]
WalletConnect disabled the rogue project, and at 2:55 p.m. the stablecoin issuer Tether froze the attackers' USDT.[1][2]
What it cost
About $600,000 in crypto and NFTs was stolen from users of affected sites, according to reporting at the time.[2] Ledger confirmed that its hardware wallets and its main Ledger Live app were not compromised.[2]
Ledger committed to tighter reviews of who can access internal and outside tools, stronger code review and release rules, a third-party audit of access controls in early 2024, better monitoring, and more phishing training.[1] The episode became a widely cited example of a software supply chain attack, where one trusted component is poisoned to reach many downstream users.
The missing control
The missing control: revoking every external account at offboarding, not just internal ones. The former employee's internal access was cut off, but the outside account that could publish Connect Kit was left open.[1]
If that npm access had been removed the day the employee left, the phishing attack would have captured an account with no power to publish anything. A full list of outside services each employee can reach, checked at every departure, turns a gap like this into a routine box to tick.
What to do in your business
- List the outside accounts. For each role, write down the external services it uses, such as your website host, domain registrar, social media, payment processor and code or app stores.
- Offboard from the list. When someone leaves, go through every item and remove or transfer access the same day, not only their email and laptop.
- Use company-owned accounts. Where you can, keep admin rights on accounts the business controls, and add people as members you can remove, rather than letting a staff member own the account.
- Protect publishing rights. Limit who can change your website, apps or public code, and turn on the strongest login protection each service offers.
- Review access every quarter. Once every 3 months, check who still has access to each outside service and remove anyone who does not need it.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.