Post

Log inSign up

Post

Log inSign up

Mudit Gupta on X: "The ledger issue is now fixed. To make sure you don't have the malicious library cached, go to https://t.co/MSVgii7Ufk and ensure the version is 1.1.8. If it's not, clear your cache. chrome- F12> Chrome Developer Tools > Application tab > Storage in left tree> Clear site data."

@Mudit__Gupta
Mudit Gupta
Polygon
@Mudit__Gupta
The ledger issue is now fixed. To make sure you don't have the malicious library cached, go to cdn.jsdelivr.net/npm/@ledgerhq/… and ensure the version is 1.1.8. If it's not, clear your cache. chrome- F12> Chrome Developer Tools > Application tab > Storage in left tree> Clear site data.
2:09 PM · Dec 14, 2023·
849.2K
Views
165

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email

Relevant people

Avatar
Mudit Gupta@Mudit__GuptaFollow
CTO @0xPolygon Labs | Blockchain Security Researcher | Ethereum & Web3 dev 🦇🔊

Trending now

Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • @Mudit__Gupta
    Mudit Gupta
    Polygon
    @Mudit__Gupta
    The ledger issue is now fixed. To make sure you don't have the malicious library cached, go to cdn.jsdelivr.net/npm/@ledgerhq/… and ensure the version is 1.1.8. If it's not, clear your cache. chrome- F12> Chrome Developer Tools > Application tab > Storage in left tree> Clear site data.
    2:09 PM · Dec 14, 2023·
    849.2K
    Views
    165
  • @Mudit__Gupta
    Mudit Gupta
    Polygon
    @Mudit__Gupta
    Dec 14, 2023
    Do NOT interact with any dApp till you have ensured you have the fix. Some apps might be bundling the malicious library and serving directly. Although unlikely, but it's best to wait for the Apps to confirm they are safe before using them.
    5
    @Mudit__Gupta
    Mudit Gupta
    Polygon
    @Mudit__Gupta
    Dec 14, 2023
    To all dApps: please redeploy/regenerate your bundles and let the community know when it's safe to use. To all the users: If you used any dApp in last ~6 hours, go check if you still have all your money. If you have, you are safe. If you didn't use any dApp, you are safe.
    11
    @Mudit__Gupta
    Mudit Gupta
    Polygon
    @Mudit__Gupta
    Dec 14, 2023
    Luckily, the js is loaded live by default and not bundled in so if you have ensured that you have the latest version, you are safe on 99.99% of the dApps. Just to be extra sure, don't ape anywhere today. Go to sleep. Wake up tomorrow and all will be good.
    6
  • @wen_moon_ser_69
    moondogewen69.base.eth
    @wen_moon_ser_69
    Dec 14, 2023
    Bad advice. Apps not always load libraries using CDN. It's in fact more common that they use a bundler, like Webpack to embed the libraries into their code. In this case the app needs to be rebuilt and redeployed by developers. But first developers need to know about the hack.
    1