Been up for 5 minutes but here's my understanding:
- A malicious ledger connectkit package was published to npm by a compromised privileged account. - this package gets hotloaded so it was immediately in use by most dapps that use connectkit (most dapps) - it has since been patched so dapps should now behave as normal.
To be clear: your ledger device is not compromised, though your trust in ledger may be.
If you want to stay safe, touch grass for a few more hours.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Been up for 5 minutes but here's my understanding:
- A malicious ledger connectkit package was published to npm by a compromised privileged account.
- this package gets hotloaded so it was immediately in use by most dapps that use connectkit (most dapps)
- it has since been patched so dapps should now behave as normal.
To be clear: your ledger device is not compromised, though your trust in ledger may be.
If you want to stay safe, touch grass for a few more hours.