RevokeCash / revoke.cash

❌ Revoke or update your token approvals
https://revoke.cash
MIT License
674 stars 238 forks source link

Security impact of @LedgerHQ/connect-kit hack? #158

Closed lachesis closed 10 months ago

lachesis commented 10 months ago

connect-kit was hacked recently: https://github.com/LedgerHQ/connect-kit/issues/29

Revoke.cash was specifically called out as compromised: https://twitter.com/RevokeCash/status/1735282669808717958?t=bnVdCMZlMyAkuuTaFokaaA

Can you speak more about the current state of revoke.cash and what mitigations you are taking to prevent a supply chain attack from compromising revoke.cash again? As a dApp security tool, revoke.cash has an obligation to do better than the average pump-and-dump crypto scheme.

rkalis commented 10 months ago

You are absolutely right that we should do better than your average crypto website. We'll publish a statement about this later today.

rkalis commented 10 months ago

We published our statement here: https://revoke.cash/blog/2023/ledger-connect-kit-hack-retrospective