BREAKING: Sushi DeFi Security Breach: CTO Sounds Alarm, SUSHI Price Drops 4%
In a significant blow to the decentralized finance (DeFi) sector, the Sushi DeFi protocol has fallen victim to its second exploit this year. The protocol’s Chief Technology Officer (CTO), Matthew Lilley, has issued a sta...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
In a significant blow to the decentralized finance (DeFi) sector, the Sushi DeFi protocol has fallen victim to its second exploit this year.
The protocol’s Chief Technology Officer (CTO), Matthew Lilley, has issued a stark warning to users, advising them to refrain from using any decentralized applications (dApps) until further notice.
Sushi And Zapper Frontends CompromisedThe latest breach has prompted concerns about the security and integrity of the Sushi DeFi protocol and other associated dApps. According to Lilley, a widely-used web3 connector has been compromised, allowing malicious code injection that affects numerous dApps.
Specifically, dApps that use the LedgerHQ/connect-kit, a dApp that allows users to connect other dApps to their Ledger hardware wallets, are considered vulnerable. Notably, Lilley’s warning underscores the severity of the situation, emphasizing that this is not an isolated attack, but a large-scale assault targeting multiple dApps.
Further investigation by security experts has revealed a potential supply chain attack on the ledger connect kit. The attacker allegedly successfully injected a wallet-draining payload into the popular Node Package Manager (NPM), impacting several prominent dApps, including Hey and others.
Additionally, it has been discovered that the Zapper and Sushi frontends have been hijacked, exacerbating the scope of the breach.
Slowmist, a module of Ledger, further confirmed that their system was hijacked and tampered with during the supply chain attack. This compromised the integrity of the ledgerhq/connect-kit library, which is relied upon by many dApps.
As a result, users are urged to exercise caution when conducting any dApp-related operations and to scrutinize requests for wallet information that may appear unexpected.
Malicious Connect Kit Neutralized?In an official statement, Ledger has confirmed the identification and removal of a malicious version of the Ledger Connect Kit. The company assures users that their Ledger devices and Ledger Live remain uncompromised.
The company stated that a genuine version of the Connect Kit is currently being pushed to replace the malicious file. Ledger advises users to refrain from interacting with any dApps at the moment for their safety.
The company pledges to provide updates as the situation develops, ensuring users stay informed about the ongoing efforts to address the security breach.
SUSHI’s Uptrend Threatened By Exploit FalloutIn light of recent events affecting the Sushi DeFi protocol, its native token, SUSHI, has experienced a decline of over 4% within the past hour, reaching a low of $1.590.
Before the exploit, SUSHI had been exhibiting a notable uptrend structure on its 1-day chart, marked by higher highs and higher lows. However, with the loss of its crucial support level at $1.961, there is a potential invalidation of the previously established uptrend.
The uncertainty surrounding the protocol’s native token raises the possibility of further downside in SUSHI’s price action. If a sustained downtrend continues, the next significant support level for SUSHI is located at $1.084.
Featured image from Shutterstock, chart from TradingView.com
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on NewsBTCRelated market context
Sui’s Hashi Launches With $500M to Turn Bitcoin Into Productive DeFi Collateral Markets
Key Takeaways: With more than $500 million in locked-in tokens, Hashi will launch its phased mainnet launch. The protocol enables...
Aave MCP now connects with MetaMask Agent Wallet for AI-driven DeFi actions
AI-driven DeFi integration enhances automation and security, empowering users with greater control and developers with streamlined...
XRPL’s $1.34 billion stablecoin base doesn’t tell us how much XRP users need
Tracked stablecoins on the XRP Ledger totaled $1.338 billion on Oct. 7. For XRP holders, the critical question is how much activit...
Bitcoin holder loses 80 BTC worth $5.2 million after moving funds to reseller-bought Ledger
The incident underscores the critical importance of purchasing hardware wallets from official sources to ensure asset security. Th...
Tether freezes USDT linked to Ledger user thefts near $90 million
The freeze highlights the need for robust supply chain security and raises concerns about the limitations of centralized control i...
Tether Freezes USDT Linked to Ledger User Thefts, MistTrack Says
MistTrack puts reported losses near $90 million as Ledger asks reseller CryptoBilis to halt device sales and shipments.... Read th...