pull down to refresh
0 sats \ 1 reply \ @0xbitcoiner OP 14 Dec 2023 \ parent \ on: We have identified and removed a malicious version of the Ledger Connect Kit bitcoin
If it's an inside job, it's very bad. Basically everything could be compromised.
Shouldn't the commits be multi-keyed?
edit: multisig
I don't know how ledger runs their business, but I got a screenshot of a tweet from another chat (twitter user @MatthewLilley) which says
- They are loading JS from a CDN
- They are not version locking loaded JS
- They had their CDN compromised
reply