Ledger CTO Warns of Supply Chain Attack Affecting Crypto Transactions
- The NPM account of a reputable developer was compromised, leading to a large-scale supply chain attack.
- Malicious packages downloaded over 1 billion times contain code that swaps crypto addresses to steal funds.
- Hardware wallet users are advised to verify every transaction before signing.
- Software wallet users face greater risks and should avoid onchain transactions until resolved.
- The attack could potentially affect all chains, with efforts underway to remove malicious code.
The Ledger CTO highlighted a significant threat from a compromised NPM account affecting over one billion downloads. Users of hardware wallets should verify transactions, while software wallet users are at increased risk and should avoid onchain activities.
Source (3.2)https://cryptobriefing.com/ledger-cto-check-onchain-transactions/?rand=59535