Been up for 5 minutes but here's my understanding:
- A malicious ledger connectkit package was published to npm by a compromised privileged account. - this package gets hotloaded so it was immediately in use by most dapps that use connectkit (most dapps) - it has since been patched so dapps should now behave as normal.
To be clear: your ledger device is not compromised, though your trust in ledger may be.
If you want to stay safe, touch grass for a few more hours.
Esta página pode conter conteúdo de terceiros, que é fornecido apenas para fins informativos (não para representações/garantias) e não deve ser considerada como um endosso de suas opiniões pela Gate nem como aconselhamento financeiro ou profissional. Consulte a Isenção de responsabilidade para obter detalhes.
Been up for 5 minutes but here's my understanding:
- A malicious ledger connectkit package was published to npm by a compromised privileged account.
- this package gets hotloaded so it was immediately in use by most dapps that use connectkit (most dapps)
- it has since been patched so dapps should now behave as normal.
To be clear: your ledger device is not compromised, though your trust in ledger may be.
If you want to stay safe, touch grass for a few more hours.