最新报道:A software vulnerability in the Web3 infrastructure provider Ledger's Connect Kit led to a $140 million exploit, with hackers draining funds from multiple decentralized applications (dApps). The breach, detected on December 14, prompted Ledger to release a patched version within hours. Major platforms like SushiSwap and Revoke.cash temporarily disabled front-end interactions to mitigate risks. Blockchain analysts traced the attack to a phishing incident targeting a former Ledger employee. The compromised library was widely used, raising concerns over supply-chain security in DeFi. Ledger advised users to avoid interacting with dApps until the fix was confirmed. The incident highlights ongoing security challenges in the crypto ecosystem.