@Altcoin_Alerts posted a warning about hacking popular decentralized apps. It is highly recommended not to connect your MetaMask and similar wallets to these applications at the moment.
ALERT: Couple of popular dapps including Sushi, Zapper, Revoke Cash & more affected a attacker injected a wallet draining payload into the popular NPM package !
Also, SushiSwap's CTO Matthew Lilley tweeted (X) that:
Do not interact with ANY dApps until further notice. It appears that a commonly used web3 connector has been compromised which allows for injection of malicious code affecting numerous dApps.
Here’s their new update just now:
https://x.com/revokecash/status/1735308527814537525?s=61&t=6PFitUK4YQvupu3PxlJoIgGood thing that I did not touch my Ledger for a long while. I’ve also disconnect my Metamask from all websites just for assurance despite that it’s just a burner airdrop wallet. So my funds are SAFU.
These hackers are getting intelligent day by day and they are smart enough to target one thing that connect all of the dots which is the Web3 wallet connector itself that was being integrated by most Dapps.
For now, I am stopping all of my DeFi activities until everything is alright as they said about not interacting for a day.
As Ledger was being targeted due to its seed phrase and private key vulnerability, I am thinking of transferring them to a different hardware wallet like Tangem which has RFC cards that acts as our own main feature for security and recovery and approving of transactions.