Curriculum·G705 Scam Response for Community Leaders·about 32 min

Containment and the response clock

By the end of this lesson you can

  • State the timeline of the Ledger Connect Kit compromise of 14 December 2023: how access was obtained, when the malicious versions were published, when the fix shipped, and how long the exposure lasted
  • Explain the difference between the time to fix and the time to safe, and why the second is set by every cache, mirror and integration that carries the fix
  • Compute the exposure window from the report's own times, and read what the gap between the 40-minute fix and the five-hour resolution was made of
  • Design containment for a community incident: the kill switches that exist before the incident, the order they are pulled in, and the clock that is published afterward

Graduate · enrolled learners

This lesson opens with The Ledger Connect Kit supply chain attack, 14 December 2023.

What happened
A former Ledger employee was phished and the attacker obtained their session token for the NPM package registry, bypassing two-factor authentication; the employee's access had not been revoked when they left. Using it, the attacker published malicious versions of the Ledger Connect Kit, a library that many decentralized applications load into their front ends to connect wallets, at 09:49, 10:44 and 11:37 on 14 December, with the last carrying a wallet-draining payload that redirected users' assets to an attacker-controlled wallet. Applications including SushiSwap, Kyber, Revoke.cash and Zapper loaded the compromised library. Ledger's report states that its teams were alerted at 13:45, that a genuine version was deployed within 40 minutes, at 14:18, and that about five hours passed from the compromise to complete resolution, the extra time being the content delivery network propagating the fixed file to its caches worldwide. Ledger estimated the window in which assets were actively drained at under two hours. Independent analyses put the amount taken at about $600,000.
The decision point
The fix took forty minutes. Being safe took five hours, because a fix is not in the user's browser until every cache between the publisher and the page has picked it up, and the malicious file sat in those caches with the fixed one behind it. The report separates the two clocks honestly, and the separation is the lesson: containment is not the moment the leader does the right thing, it is the moment the last copy of the wrong thing stops being served, and every cache, mirror, pinned message, forwarded email and integration is a copy. A community leader who has pulled the post has not contained the incident until the screenshots of it, the mirror in the other server and the bot that reposts announcements have been dealt with, and the clock that gets published afterward is the second one.
Recorded loss
$600,000

What you will be able to answer

  • What happened in the Ledger Connect Kit attack?
  • Time to fix versus time to safe?
  • What are a community's caches?
  • What is a kill switch, in containment design?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Terms used here

Sources and review

Confidence high·Volatility low·Reviewed 2026-09-14·Owner unassigned

Contested

Ledger's report does not state a total amount taken; the roughly $600,000 figure is from independent on-chain analyses reported at the time and is used as the loss figure with that caveat. The report describes the actively drained window as under two hours within the five.

The report's times are given in the company's local timezone; the lesson uses them as stated and relies on the intervals rather than the absolute times.