22 ms·
Ledger's NPM account has been hacked
- ramijames 3y agoYikes.
- kossTKR 3y agoLedger has been hacked so many times now i've lost count. I remember buying one in 2019, and shortly thereafter all customer data was dumped on the internet endangering everyone who bought one. Then after deep diving the tech i threw it in the trash, it seemed like security theatre product. There's also been so many phishing attempts, fake ledgers sold, bricked ones losing funds, it's total shitshow that ecosystem if you check their subreddit going back in time. The more you rely on 3. parties, and the more obfuscated your setup is, the more unsafe your data is. I just use isolated cheap laptops and encrypted usb's now.
- lxgr 3y agoDo you build and program these laptops and USB drives yourself?
- deleted 3y ago[deleted]
- nullstyle 3y ago"bricked ones losing funds" That's the user's fault. The product makes it very clear you need to create a recovery sheet and store it in a safe deposit box or other secure place. If you actively ignore the instructions you deserve it. Could you share some of your deep dive and tell us about what concerns you found? I use one of their wallets and I'd like to investigate more now as well.
- rekoil 3y agoA few months ago they also pushed a new feature which, if enabled, literally exfiltrated your secret key to external parties, requiring only 2 to reassemble the full key... Avoid Avoid Avoid
- dboreham 3y agoThe only reason things like Ledger exist is because regular smart cards (e.g. Yubikey) don't yet support the signature schemes used on blockchains.
- meehow 3y agoRegular smart cards also don't have screens, so it would mean totally blind signing. That's the problem which hardware wallets are solving, but sometimes the screen is just too small to show all the details of complex transactions.
- chrisco255 3y agoYubikeys are fine for basic sign-in/sign-out functionality, but even on a basic web app, your auth tokens are something else independent of your Yubikey signature.
- meowface 3y ago>I just use isolated cheap laptops and encrypted usb's now. I figure this isn't practical for most end users. Is there an alternative hardware wallet that you think is okay for most people? How do you feel about Trezor?
- Rastonbury 3y agoI don't know which it more practical trusting an exchange, paying a hardware wallet or maybe encrypted file in s3
- anders16 3y agoColdcard! https://coldcard.com/ https://coldcard.com/
- yownie 3y agoI'm curious about coldcard as well, however what would you say are the benefits over a trezor / ledger device?
- bdd8f1df777b 3y agoHow? My set up is less secure, but more auditable than hardware wallets--a dedicated hard disk running a portable Linux doing nothing else than crypto. And only for sending out funds. For receiving funds I use my normal operating system with view-only keys.
- pants2 3y agoThe modern solution is to use MPC wallets like ZenGo.
- ametrau 3y agoI must be missing something. It couldn’t be as dumb as using a photo of your face as the key.
- arifromzengo 3y ago
- irusensei 3y agoSame here. The most infuriating thing is how they downplayed the data breach, specially considering some of their customers live in dangerous countries. I’ve switched to a Coldcard. Everything from purchase to the device operation seems to be highly focused on security and protections against tampering. No client software… it’s all sneakernet. Coinkite even deleted my customer data a few weeks after purchase without me having to request. I still have my ledger. I think it is a nice device but when I tried to repurpose it as an yubikey of sorts (it has fido and gpg micro apps) it didn’t actually worked alright. I never trusted ledger live though.
- matheusmoreira 3y agoI've found the most secure key management is to keep important keys offline and stored on paper and only load them into a live tails/whonix system for brief uses. I even contributed a binary decoding feature to zbar to let me store them on printed QR codes and easily input them back in. > bricked ones losing funds Well of course. It's just a computer and all computers fail. Cheap laptops can also fail and destroy your keys. USB flash storage failure is even more likely. This is the number one argument for storing keys on paper which is actually known to last centuries.
- magento 3y agoPhishing attempts are irrelevant as long as users check TXes before they sign. Fake ledgers are also irrelevant because the software does a check if the hardware is legit. Bricked Ledgers losing funds is only a thing if a user didn't keep a backup of their seed phrase, which would make them lose funds regardless of what wallet they used.
- binarymax 3y agoNPM forces 2fa, so I’m curious what the scenario was here. Was a committers phone compromised?
- rdl 3y agoGithub action
- rdl 3y agoActually worse than that, former employee phished for credentials, per Ledger themselves. Underlying cause is utter incompetence by company, 4th strike.
- Daviey 3y agoThe Github action leaked the creds, seemingly via a log. Looks like that action has been in use for ~4 months.
- koolba 3y agoAutomated publishing without a human involved kind of kills the whole point of 2FA anyway. It is kind of funny that the crypto world of multi sigs relies on blind trust of unverified UI components.
- deleted 3y ago[deleted]
- latchkey 3y agoTechnically, it is just the frontends. You can always interact with the contracts directly and that can't ever be shut down (if you know what you're doing). Can you do that with your bank? Let's also not forget that every other website on the planet that relies on npm also relies on the blind trust of unverified UI components. This isn't just silo'd to crypto.
- 3y ago
- nathell 3y agoJust yesterday I watched a talk [0] at WarsawJS about LavaMoat [1], a set of tools to protect against malicious behaviour from npm dependencies. Guess it’s time to look into it deeper. [0]: https://naugtur.pl/pres3/lava/2023end.html https://naugtur.pl/pres3/lava/2023end.html [1]: https://github.com/LavaMoat/LavaMoat https://github.com/LavaMoat/LavaMoat
- beeboobaa 3y ago[flagged]
- capableweb 3y agoPretty shitty of that accounting software to reuse a name that has been used for paper accounting since basically forever. Or, we can have multiple things being called the same thing, as RTFA actually makes the context clear.
- darrenf 3y agoPer HN guidelines, emphasis mine: "Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- zaphod420 3y agoOne of the comments on the github issue... https://github.com/LedgerHQ/connect-kit/issues/29 https://github.com/LedgerHQ/connect-kit/issues/29 "The @ledgerhq/connect-kit-loader allows dApps to load Connect Kit at runtime from a CDN so that we can improve the logic and UI without users having to wait for wallet libraries and dApps updating package versions and releasing new builds. This looks like an extremely dangerous approach now, if I understand it correctly, connect-kit-loader trusts whatever the CDN throws at your dApps. So when connect-kit is comprised, all downstream dApps are automatically exposed."
- lxgr 3y agoIs there even an alternative? Once you can inject arbitrary code into a library that a web app loads and executes (except if it’s in an iFrame), it’s game over, no?
- chrisandchris 3y agoPartially, one could use a Content-Security-Policy to lock things further down.
- meehow 3y agoSo it was intended to be used this way. Didn't work very well. Connect-kit-loader trusts whatever the CDN throws, CDN trusts whatever NPM throws and NPM trusts whatever GitHub throws.
- cantSpellSober 3y ago> Yes, .5/.6/.7 versions are compromised So was there a threat to Ledger users? Elsewhere it's said: > production build failed
- deleted 3y ago[deleted]
- ashishbijlani 3y agoPlug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawning of shell, invalid/expired email (i.e., no 2FA), use of files, network communication, use of decode+eval, mismatch of GitHub code vs packaged code, and several more. 1. https://github.com/ossillate-inc/packj https://github.com/ossillate-inc/packj
- aftbit 3y agoCan you show the result of running a scan against this compromised repo? Would your tool have caught this crypto drainer live on revoke.cash?
- cmeacham98 3y agoTried it myself and they don't appear to have implemented the part of the scan that would catch this, relevant snippet from the logs: [+] Analyzing repo-pkg src code match.... N/A [Coming soon!]
- capableweb 3y agoAnd since you're bragging/plugging it here, I take it you tested it against this repository+version and it detected it?
- deleted 3y ago[deleted]
- rdl 3y agoLOL https://twitter.com/Ledger/status/1735326240658100414 https://twitter.com/Ledger/status/1735326240658100414 FINAL TIMELINE AND UPDATE TO CUSTOMERS: 4:49pm CET: Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again. The investigation continues, here is the timeline of what we know about the exploit at this moment: - This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account. - The attacker published a malicious version of the Ledger Connect Kit (affecting versions 1.1.5, 1.1.6, and 1.1.7). The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet. - Ledger’s technology and security teams were alerted and a fix was deployed within 40 minutes of Ledger becoming aware. The malicious file was live for around 5 hours, however we believe the window where funds were drained was limited to a period of less than two hours. - Ledger coordinated with @WalletConnect who quickly disabled the the rogue project. - The genuine and verified Ledger Connect Kit version 1.1.8 is now propagating and is safe to use. - For builders who are developing and interacting with the Ledger Connect Kit code: connect-kit development team on the NPM project are now read-only and can’t directly push the NPM package for safety reasons. - We have internally rotated the secrets to publish on Ledger’s GitHub. - Developers, please check again that you’re using the latest version, 1.1.8. - Ledger, along with @Walletconnect and our partners, have reported the bad actor’s wallet address. The address is now visible on @chainalysis . @Tether_to has frozen the bad actor’s USDT. - We remind you to always Clear Sign with your Ledger. What you see on the Ledger screen is what you actually sign. If you still need to blind sign, use an additional Ledger mint wallet or parse your transaction manually. - We are actively talking with customers whose funds might have been affected, and working proactively to help those individuals at this time. - We are filing a complaint and working with law enforcement on the investigation to find the attacker. - We’re studying the exploit in order to avoid further attacks. We believe the attacker’s address where the funds were drained is here: 0x658729879fca881d9526480b82ae00efc54b5c2d Thank you to @WalletConnect , @Tether_io, @Chainalysis , @zachxbt , and the whole community that helped us and continue to help us identify and solve this attack. Security will always prevail with the help of the whole ecosystem.
- rdl 3y ago1) They are using some phishable auth (SMS? TOTP? password only?) to secure super high value repo? For fuck's sake, they're a HARDWARE KEY VENDOR which also supports U2F/FIDO2 as an app. 2) Former employee has signing/push auth on super high value repo? 3) Single person has signing/push auth on super high value repo? .com
- pockmockchock 3y ago[flagged]
- woah 3y agoHow did the exploit work? Obviously it looks really bad for Ledger to keep having these web security failures, but the entire point of a hardware wallet is to make it so that you don't have to rely on the security of the code on your computer. If the hardware wasn't compromised (sounds like this was just JS), then there was no way for the exploit to take anyone's private key. It sounds to me like the exploit would work by getting you to sign a transaction that would transfer out the funds, without the attacker ever getting your key. The only way this is possible is if users are signing transactions on their Ledger without looking at them. And this is place where the Ethereum community needs to look in the mirror. Blind signing is the default for using Ethereum with a Ledger. I'm not sure the technical reasons behind this, but I do happen to know that much of the information that gets signed is in very convoluted formats (meta transactions etc). This is not the case everywhere. Other ecosystems, like Cosmos, present the information to be signed in a plain text format that you can scroll through on the Ledger's screen before you sign it. Ethereum needs to put some serious effort into making sure that anything that gets signed can be viewed in a human-readable format before signing. Until then, hardware wallets are security theater.
- chrisco255 3y ago> The only way this is possible is if users are signing transactions on their Ledger without looking at them. This is correct. Estimates are that the attackers successfully phished about $600K.
- wyck 3y agoYou can see a technical analysis here https://twitter.com/Neodyme/status/1735337711555285261 https://twitter.com/Neodyme/status/1735337711555285261 , this is a JS repo for app integrations for Ledger and really has nothing specifically to do with Ethereum itself or any hardware. There are several wallets solutions that make transactions easier and more secure for people using Eth, but Eth is a protocol running a network and doesn't concern itself with the app layer, and rightly so.
- woah 3y agoYea my point is that Ethereum has created a complex system without paying enough attention to generating human-readable signing blobs. This is not something that a wallet can help with. The information displayed on the Ledger's screen needs to be human readable so that people know what they are signing. This is something that needs to be solved by the community creating transaction format specifications and the people writing the Ledger Ethereum app. Ledger deserves a lot of criticism for insecure JS, but the whole point of a hardware wallet is not to have to worry about the JS you are running.
- coneonthefloor 3y ago> Discover what security feels like Quote from their sales site.
- mecsred 3y agoFeels pretty apt honestly. This is about how secure I feel using modern technology. The only thing that makes me ok using a bank is knowing I can go ask a human being to chase my money down when it vanishes suddenly. There's even a non-zero chance they get it back to me!
- matheusmoreira 3y agoSecurity is not absolute. Even cryptographic hardware can be vulnerable. Yubico for example had to replace many of their YubiKeys after a vulnerability was detected in its secure element firmware which affected the strength of keys generated on the device. They sent me a replacement YubiKey after I contacted them. https://www.yubico.com/support/security-advisories/ysa-2017-01/ https://www.yubico.com/support/security-advisories/ysa-2017-...
- oefrha 3y agoPretty fascinating that the malicious code doesn’t seem to be obfuscated one bit. Even contains the word “drain” in multiple places. At least use innocuous looking variable names ffs.
- NoGravitas 3y agoLOL, I initially thought this was Ledger, the command-line personal finance management software, and was worried that it was actually something important.
- NoGravitas 3y agoDownvoters are wondering where their apes went.
- kiney 3y agoI though the same. (even though I personally use beancount for plain text accounting)
- asylteltine 3y agoWhen will npm finally take security seriously? How many incidents do they need? Don’t allow non hardware mfa and add verified namespaces already!
- lainga 3y agoNever. It is this way for cosmogonical reasons; it fulfils a purpose. I see Isaac Schlueter as the modern Genghis: "If you had not committed great sins, God would not have sent a punishment like me upon you."
- mikeryan 3y agoIt’s not NPMs job to secure your repo. They provide the tools to protect it. It’s your job as a maintainer to not shoot yourself in the foot.
- neom 3y agoI thought the whole point of ledger was that it's a physical wallet that can't easily be compromised. Not your keys not your crypto and all that?
- chrisco255 3y agoThis was a UI popup that got injected into the middleware provided by Ledger that is used to make it easy for apps to prompt Ledger users for a signature. The keys aren't compromised by this attack, this is more similar to a phishing attack, but via supply chain to increase fake legitimacy.
- feross 3y agoWe've been building Socket [1] to detect and block this exact type of supply chain attack. Our Socket AI scanner [2] successfully detected this attack. It uses dozens of static signals combined with an LLM to detect novel attacks that evade traditional scanning tools. This is what Socket AI produces when given @ledgerhq/connect-kit 1.1.7 to analyze: > The obfuscated code block is highly suspicious and likely contains malicious behavior. The presence of obfuscation and the unclear purpose of the code raise significant red flags. Feeling very proud of our team right now as this validates that our static analysis + LLM approach works well on novel malicious dependencies. If you're interested, we maintain a listing of malicious packages detected by this system [3]. Small plug: If you’d like real-time protection against attacks like this, you can install Socket for GitHub to automatically scan every PR in your repo. The free plan is incredibly generous. If you do decide to install it, it’s important that you enable the ‘AI Detected Security Risk’ alert type in your Security Policy to activate this protection. [1]: https://socket.dev https://socket.dev [2]: https://socket.dev/blog/introducing-socket-ai-chatgpt-powered-threat-analysis https://socket.dev/blog/introducing-socket-ai-chatgpt-powere... [3]: https://socket.dev/npm/issue/malware https://socket.dev/npm/issue/malware
- ryanjshaw 3y agoDo you discuss anywhere what you use for static analysis? I skimmed through your blog but didn't see any details. Also -- did you detect and publish this BEFORE it became public knowledge? It's unclear.
- feross 3y agoWe've built our own minimalist static analysis engine that only supports scanning for the specific supply chain threats we care about. For that reason, it's a lot simpler and faster than a generic engine. I'll see if we can write up a bit about how it works in a future blog post.
- theteapot 3y agoApparently 1.1.5|6 we're also compromised?
- jbirer 3y agoI only have a Ledger because my required me in order to implement a crypto wallet on the website. I have 2 seed phrases written on the back of a book since 2017 and it has kept me well, no hacks so far.
- resolutebat 3y agoHave you turned it on recently? Mine bricked itself with no warning.
- lrvick 3y agoAnd once again calls to allow optional signing support natively to NPM will be rejected citing that it might intimidate drive-by devs who do not want to learn to setup a yubikey or nitrokey for artifact signing. I have talked to the NPM team about this multiple times over the last several years and they literally believe no signing at all is better than some devs feeling pressured to sign. You need no stronger evidence of the NPM teams negligence than these two times they refused to even accept community contributed optional signing support saying they would come up with something better than PGP. Still waiting 10 years later. https://github.com/npm/npm/pull/4016 https://github.com/npm/npm/pull/4016 https://github.com/node-forward/discussions/issues/29#issuecomment-144505785 https://github.com/node-forward/discussions/issues/29#issuec... Meanwhile PGP secures the supply chain of the Linux distros that power the whole internet, and Debian signs hundreds of npm packages used in their dependency graph, but it is still not good enough for NPM. You can use the well tested and rust-written Sequoia/sq now and never touch GnuPG. You can also self certify your keys with keyoxide. The past complaints are largely moot and still people stick to their guns on this. https://openpgp.dev/book/ https://openpgp.dev/book/
- feross 3y agoThis isn't quite accurate. In fact, npm did ship a form of code signing called 'npm provenance' in April 2023. We wrote a semi-official deep dive on the feature in cooperation with the npm team that explains how to sign your npm packages [1]. You can see npm provenance in action on this npm package page [2] if you scroll to the very bottom and look under the "Provenance" heading. [1]: https://socket.dev/blog/npm-provenance https://socket.dev/blog/npm-provenance [2]: https://www.npmjs.com/package/@socketsecurity/cli https://www.npmjs.com/package/@socketsecurity/cli
- lrvick 3y agoI am sure virtually everyone understands "code signing" to mean what it has meant historically. The author of code signs git commits, or a tarball, or signing a package as in the debian, arch, guix sense. All of which typically share cryptography standards like PGP rather than rolling their own solutions. Each maintainer has a signing key to identify themselves to the public without need for any central infra, and signs the packages they publish. Someone that accesses some centralized server or account will not be able to impersonate the key held by that developer or the signatures they issue. This new provenance system and the fulcio system which it is based on, is a centralized setup where you use traditional, usually phishable, authentication with a SaaS, and then the SaaS takes your submission and signs it for you with a centrally managed keychain. Having done security auditing for many fintech signing systems, I can tell you I have almost never once seen anyone get this right, particularly when there is no accountability. Is this done in a secure enclave with a public remote attestation of the software image running on it that I can locally compile and verify the matching hash of? Does that code enforce the participation of multiple distributed people to make updates, key exports, or key imports using shamirs secret sharing or similar? Or maybe it is just sitting on an amazon box somewhere a few people ssh to from their daily driver macbooks ? I don't -hate- centralized signing existing as an -option- if it is done very well and highly accountable (which fulcio is not, imo). That said, -mandating- centralized signing on behalf of developers as the only path is really insulting, as though people who write software can't type a couple commands to provision a PGP key on a smartcard and publish their key to keyoxide which is strictly better in every way from a threat modeling perspective. Speaking of Fuclio, this was meant to "invent" a solution for container signing, even though PGP multisig has existed from the start. No one used it because none of the major players in container software documented it other than the podman team. https://github.com/containers/image/blob/main/docs/containers-policy.json.5.md https://github.com/containers/image/blob/main/docs/container... https://docs.podman.io/en/latest/markdown/podman-image-trust.1.html https://docs.podman.io/en/latest/markdown/podman-image-trust... Back to NodeJS, Debian and Arch already sign npm packages with PGP keys. It works fine. We need to let people actually do that with NPM. Tell me how many supply chain attacks have happened in Debian or Arch recently compared to NPM? PGP may be a small barrier to entry, but it is a standard with solid smartcard support and works in practice. It should be the default recommendation to all developers, and end users should be able to set policies to only install packages signed by a trusted set of maintainer or reviewer keys.
- albertaaura99 3y ago[dead]
- wslh 3y agoI have round up more information on this issue and the context here [1]. [1] https://news.ycombinator.com/item?id=38646314 https://news.ycombinator.com/item?id=38646314
- louislang 3y agoCo-founder @ Phylum here (https://phylum.io https://phylum.io). We've been actively scanning dependencies across most open source package registries (e.g., npm, PyPI, Crates.io, etc.) for a few years now. Quite successfully, I might add, with recent findings targeting financial institutions [1], North Korean state actors [2], and some of the first malware staging to be seen on Crates.io [3]. The fact that an attacker was able to pull this off against a _secure_ hardware device is shocking but not surprising. The mechanism by which they did it is interesting and fairly insidious. Unlike a lot of other attacks that will publish the malware to the registry, this one pulls the payload from a CDN. So, static analysis of the loader (i.e., the intermediary package on npm) is unlikely to yield sufficiently interesting results. Solely focusing on the obfuscation angle is also not of particular use since quite a bit of packages are obfuscated on npm (like, a surprising amount of it. In Q3 2023 we saw over 5,000 _new_ packages shipped with some form of obfuscation). Nonetheless, our automated platform pinged us this morning about some changes to this package and our research team has been digging into it to determine the impacts. With that said, we've produced (and open sourced!) several tools that aim to help with software supply chain style attacks: 1. Birdcage is a cross-platform embeddable sandbox [4] 2. Our CLI is extensible and integrates Birdcage so you can do things like `phylum npm install...` or `phylum pip install...` and have the package installations be sandboxed [5] We've also got a variety of integrations [6] along with a threat feed of software supply chain attacks (of which the Ledger package and other APT attacks have appeared). Happy to answer any questions! A collective of us are active in Discord (https://discord.gg/Fe6pr5eW6p https://discord.gg/Fe6pr5eW6p), continuing to hunt attacks like these. If that's something that interests you, we'd love to have you! 1. https://blog.phylum.io/encrypted-npm-packages-found-targeting-major-financial-institution/ https://blog.phylum.io/encrypted-npm-packages-found-targetin... 2. https://blog.phylum.io/junes-sophisticated-npm-attack-attributed-to-north-korea/ https://blog.phylum.io/junes-sophisticated-npm-attack-attrib... 3. https://blog.phylum.io/rust-malware-staged-on-crates-io/ https://blog.phylum.io/rust-malware-staged-on-crates-io/ 4. https://github.com/phylum-dev/birdcage https://github.com/phylum-dev/birdcage 5. https://github.com/phylum-dev/cli https://github.com/phylum-dev/cli 6. https://docs.phylum.io/docs/integrations_overview https://docs.phylum.io/docs/integrations_overview
- tamimio 3y ago>minimal drain value I actually laughed! Anyway, this is the list of affected software github.com/wevm/wagmi github.com/wevm/wagmi github.com/family/connectkit github.com/scaffold-eth/scaffold-eth-2 github.com/RevokeCash/revoke.cash github.com/blocknative/web3-onboard github.com/blocknative/web3-onboard github.com/liquity/dev github.com/matter-labs/zksync-wallet-vue github.com/bankisan/zkShield github.com/zkemail/zk-email-verify github.com/iron-wallet/iron github.com/gmx-io/gmx-interface github.com/blocknative/web3-onboard github.com/reservoirprotocol/reservoir-kit github.com/daimo-eth/daimo github.com/AztecProtocol/aztec-packages github.com/lifinance/widget github.com/matter-labs/zksync-dapp-checkout github.com/gnosis/zodiac-modifier-roles github.com/scaffold-eth/Scaffold-ETH-DeFi-Challenges github.com/cowprotocol/cowswap github.com/cowprotocol/cowswap github.com/cowprotocol/cowswap github.com/canvasxyz/canvas github.com/lifinance/widget github.com/parity-asia/hackathon-2023-summer github.com/ubiquity/ubiquity-dollar github.com/TalismanSociety/talisman-web github.com/BanklessDAO/bankless-website github.com/lifinance/widget github.com/TalismanSociety/talisman github.com/zkemail/proof-of-twitter github.com/Ifechukwudaniel/Oracles github.com/Ifechukwudaniel/Oracles github.com/noir-lang/noir-examples github.com/voteagora/agora github.com/coinbase/build-onchain-apps github.com/Midas-Protocol/monorepo github.com/austintgriffith/stupid-staking github.com/MetaMask/metamask-sdk github.com/threshold-network/token-dashboard github.com/threshold-network/token-dashboard github.com/privacy-scaling-explorations/bandada github.com/lidofinance/lido-ethereum-sdk github.com/haqq-network/frontend github.com/reservoirprotocol/seaport-oracle github.com/ameensol/pools-ui github.com/Web3Auth/web3auth-wagmi-connector github.com/Orbiter-Finance/zkprover-dapp github.com/xmtp/xmtp-web github.com/etherspot/etherspot-react-transaction-buidler-demo-dapp github.com/base-org/web github.com/unlock-protocol/examples github.com/saRvaGnyA/decertify github.com/scaffold-eth/OP-RetroPGF3-Discovery-Voting github.com/lukso-network/universalprofile-test-dapp github.com/ScopeLift/token-shielder github.com/givepraise/praise github.com/0xRusso/fr3ela github.com/BreadchainCoop/breadchain-crowdstaking github.com/unstoppabledomains/uauth github.com/unstoppabledomains/uauth github.com/hyperlane-xyz/hyperlane-warp-ui-template github.com/mento-protocol/mento-web github.com/harendra-shakya/blockchain-lottery github.com/harendra-shakya/blockchain-lottery github.com/harendra-shakya/blockchain-lottery github.com/harendra-shakya/blockchain-lottery github.com/Koniverse/SubConnect github.com/saqlain1020/dapp-react-typescript-boiler github.com/carletex/notion-eip712 github.com/BuidlGuidl/event-wallet github.com/scobru/nimbus2000-ui github.com/scobru/nimbus2000-ui github.com/yieldprotocol/cacti-frontend github.com/BuidlGuidl/hacker-houses-streams github.com/jaxernst/scp github.com/bee-io/web3-connect github.com/bee-io/web3-connect github.com/bee-io/web3-connect github.com/moodysalem/eth-batch-deposit github.com/AztecProtocol/zk-money github.com/BuidlGuidl/zupass-scaffold-eth-2 github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/LedgerHQ/connect-kit github.com/elmol/zk-proof-of-humanity github.com/swing-xyz/examples github.com/ahmetson/nft-bridge github.com/RogerPodacter/gas-lovers-nft github.com/kmjones1979/scaffold-eth-2-solidity github.com/irfanbozkurt/flashbot-recovery-bundler github.com/amy-jung/collectivedaoarchives.catalog github.com/ERC-3643/ERC-3643-DApp github.com/austintgriffith/impersonator-vision github.com/scaffold-eth/SablierV2_starterKit github.com/gnosis/mech npm/web3-onboard/ledger npm/web3-onboard/ledger npm/web3-onboard/ledger github.com/succinctlabs/telepathy-messenger-demo github.com/Votes-Project/votes-web github.com/wevm/wagmi github.com/cowprotocol/cowswap
- activescott 3y agoShouldn't this be considered an incident at https://status.ledger.com/ https://status.ledger.com/ ??