Ledger Connect Kit supply-chain attack: malicious library version drained ~$600K from users blind-signing on EVM dApps; Ledger committed to make victims whole via a claims process (by Feb 2024). Status: Ledger committed to reimburse.
Data as of · Last updated · By VaultRubric Research · How we score · Not investment advice.
Ledger Connect Kit supply-chain attack: malicious library version drained ~$600K from users blind-signing on EVM dApps; Ledger committed to make victims whole via a claims process (by Feb 2024). Status: Ledger committed to reimburse.
| Date | 2023-12 |
|---|---|
| Type | customer funds loss |
| Products in our data affected | Ledger, Ledger Nano S Plus, Ledger Nano X, Ledger Flex, Ledger Stax |
| Reimbursement | Ledger committed to reimburse |
| Effect on VaultRubric scores | −3 security points (customer-funds loss), but still eligible because victims were shown reimbursed / reimbursement committed |
| Sources | www.ledger.com, support.ledger.com, www.theblock.co |
Facts above are taken from the cited sources as of 2026-10-11. Follow the vendor's official guidance (linked) for remediation; nothing here is security advice. How hacks affect scores.
Ledger Connect Kit supply-chain attack: malicious library version drained ~$600K from users blind-signing on EVM dApps; Ledger committed to make victims whole via a claims process (by Feb 2024).
Ledger committed to reimburse.
Ledger, Ledger Nano S Plus, Ledger Nano X, Ledger Flex, Ledger Stax.
−3 security points (customer-funds loss), but still eligible because victims were shown reimbursed / reimbursement committed.