A secure key can still sign an unsafe request.
Why it matters
Wallet security includes the code that constructs and explains a request—not only the device holding a key.
Known
Ledger documented the compromised publishing path, affected package versions, exposure window and remediation. Its postmortem is the primary operator account and should be read with that role visible.
Blast radius
A shared dependency can reach many interfaces quickly. Actual loss still depends on which applications loaded the code and which users approved malicious requests.
Trust boundary
The boundary crossed employee access, package registries, release controls, application dependency policies, wallet simulation and the user's ability to verify intent.
Durable lesson
Short-lived credentials, hardware-backed publishing, dependency pinning, reproducible builds, transaction simulation and rapid ecosystem alerts reduce—not eliminate—this class of risk.