Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Onboard Ledger Connect Kit deps #2027

Closed
1 task done
tuckerchapin opened this issue Dec 14, 2023 · 2 comments
Closed
1 task done

Update Onboard Ledger Connect Kit deps #2027

tuckerchapin opened this issue Dec 14, 2023 · 2 comments
Assignees
Labels
bug Something isn't working

Comments

@tuckerchapin
Copy link

Current Behavior

Ledger recently announced a vulnerability in Ledger Connect Kit which Onboard depends on.

Expected Behavior

No response

Steps To Reproduce

No response

What package is effected by this issue?

@web3-onboard/ledger

Is this a build or a runtime issue?

N/A

Package Version

Latest

Node Version

No response

What browsers are you seeing the problem on?

No response

Relevant log output

No response

Anything else?

No response

Sanity Check

  • If this is a build issue, I have included my build config. If this is a runtime issue, I have included reproduction steps and/or a Minimal, Reproducible Example.
@tuckerchapin tuckerchapin added the bug Something isn't working label Dec 14, 2023
@tuckerchapin tuckerchapin changed the title Is Onboard insulated from/aware of the recent compromise of Ledger? Update Onboard Ledger Connect Kit deps Dec 14, 2023
@Adamj1232
Copy link
Member

Blocknative’s Web3-Onboard pulls in the latest Ledger Connect Kit update. It is now pulling in 1.1.8. Please ensure you are using the latest version of Web3-Onboard let us know if you have any questions

We are working closely with the Ledger team as they improve and update their processes for the Ledger dependencies.

According to the Ledger team the malicious software was only delivered for 5 hours and believed to only be active for two - https://twitter.com/Ledger/status/1735326240658100414

Also for avoidance of doubt:

To confirm you are on the latest version, load dapp, select Ledger from the Web3-onboard option, open developer console, select Sources tab and expand the folder shown in the image below.

Screenshot 2023-12-14 at 09 28 18

@clathrop
Copy link

Can you address whether or not users utilizing the ledger connect kit via web3-onboard are potentially still vulnerable due to browsers cacheing the delivered package? Seems like the max-age for the package is 7 days. If a user doesn't clear his or her cache they could be loading the malicious package. Be safe out there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

5 participants