Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

Tether Freezes Ledger Exploiter Loot in Wild 24 Hours for DeFi

DailyCoinDailyCoin2023/12/15 18:07
By:DailyCoin
  • Tether has frozen USDT belonging to the Ledger exploiter.
  • The exploiter made off with an estimated $600k in crypto assets.
  • The hack has been linked to a former Ledger employee.

Over the past 24 hours, a hacker spread panic across the entire DeFi ecosystem by hacking Ledger’s Connect Kit library to mount a large-scale wallet-draining exploit across multiple decentralized applications. However, this hacker’s reign of terror proved fleeting, as Ledger quickly responded with a fix. In addition to this, part of the hacker’s loot has now been frozen by Tether as investigations enter high gear.

Ledger Exploiter Loot Frozen

In an X post hours after the Ledger exploit on Thursday, December 14, Tether CEO Paolo Ardoino revealed that the firm had frozen the USDT of the hacker.

Tether just froze the Ledger exploiter address

— Paolo Ardoino 🍐 (@paoloardoino) December 14, 2023

The development comes as investigations into the attack and efforts to recover the estimated $600k in losses enter high gear. 

Per analysis of Arkham Intelligence data at the time of writing, the drainer address shared by Ledger now holds only about $274k, as the hacker has made efforts to spread the loot over the past 24 hours. The current balance includes 44k USDT, which Tether has now frozen. 

The Ledger Hack Unraveled

In a final update to customers and crypto community members at about 3:49 pm UTC on Thursday, December 14, Ledger explained that the hacker had gained access to Ledger’s internal systems by duping a former employee via a phishing attack.

FINAL TIMELINE AND UPDATE TO CUSTOMERS:

4:49pm CET:

Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.

The investigation continues, here is the timeline of what we know about…

— Ledger (@Ledger) December 14, 2023

After gaining access to Ledger’s systems, the hacker infused malicious software into the firm’s Connect Kit, which was integrated with multiple DApps to allow users to facilitate transactions from their Ledger hardware wallet. With this malware in place, the hacker was able to compromise the front end of several DApps, including SushiSwap, Zapper, and Revoke.Cash prompts unsuspecting users to connect their wallet to a drainer.

Ledger noted that the malware was up for approximately five hours, with most of the hacker’s loot obtained within the first two, likely due to prompt warnings from several influential crypto community members, including Sushi CTO Matthew Lilley.

While Ledger quickly released a fix, the firm cautioned users to wait 24 hours before using DApps that use the Connect Kit as developers may take different timelines to implement necessary changes.

The hardware wallet service provider has contacted Chainalysis for help hunting down the perpetrator and recovering user funds.

On the Flipside

  • The freezing of the Ledger exploiter’s USDT sparked renewed Tether centralization concerns within the crypto community.
  • The amount frozen by Tether represents a small fraction of the exploiter’s total loot.
  • Despite Ledger’s assurances, several crypto community members remain skeptical about using dApps that support the Connect Kit.

Why This Matters 

Tether’s action highlights that progress is being made to recoup user funds, bringing hope to victims of the recent exploit.

Read this to learn more about the Ledger hack:
Sushi CTO Warns Ledger Connector Exploited: How to Stay Safe

Find out how Polygon benefits from CCTP support:
Here’s How Polygon Benefits from Circle (USDC) CCTP Support

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

‌Spot copy trading

More
AIOnline
AIOnline
insight1000/1000
11318.51%
ROI
Total profit $57724.41
HappyPlanets
HappyPlanets
insight500/500
18780.56%
ROI
Total profit $37561.09

Bot copy trading

More
TopTrader85
TopTrader85
insight150/150
$13284.03
Total profit
Total subscriber profits $137.16
GridOnly
GridOnly
insight150/150
$9015.2
Total profit
Total subscriber profits $107.17