Bitcoin Forum
November 19, 2024, 07:51:04 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ledger Receive Wallet Attack  (Read 284 times)
#BitcoinVegan (OP)
Member
**
Offline Offline

Activity: 76
Merit: 10


View Profile
February 05, 2018, 03:28:13 PM
 #1

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
ruplikminer
Jr. Member
*
Offline Offline

Activity: 504
Merit: 3


View Profile
February 05, 2018, 03:41:10 PM
 #2

Very curious to know also
zhekinsp
Full Member
***
Offline Offline

Activity: 882
Merit: 126


★777Coin.com★ Fun BTC Casino!


View Profile
February 05, 2018, 03:54:29 PM
 #3

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.

Jaycee99
Sr. Member
****
Offline Offline

Activity: 1036
Merit: 273


View Profile
February 05, 2018, 04:13:01 PM
 #4

I thought hardware is kind a USB look alike and no one can open it until you say so.

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?

How can be this hardware wallet would be attack? What to do it to buy another hardware wallet its better safe than never. I would suggest as well to try a different wallet that is myetherwallet its safe too you know I cant offer you suggestion its up to you.


I would just say if you think your not safe anymore on working with that hardware wallet try to buy new one that us trezor its 2nd best to ledger.
Caesar-Giulius
Sr. Member
****
Offline Offline

Activity: 728
Merit: 250


Buy, sell and store real cryptocurrencies


View Profile
February 05, 2018, 04:30:39 PM
 #5

What is going on? There isn’t any news about attack on ledger wallet.

.


.
.



▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
██████████████████████████████████████
██████████████████████████████████████
███████████████████████▀██████████████
█████████▄▄      ▀▀██▀╜  ▀▀███████████
████████████▄       ██   ▀^╓▀█████████
██████████████      ║█    ,▀██████████
█████████████▄▄      █▌   ████████████
████████████████▄     ▀█▄  ███████████
████████████████▀,,,    ╙▀▀█▀ ████████
█████████████████▀▀▀█▄▄       ████████
███████████████▀     ▀███████▀████████
██████████████▌       ▐█* ▀▓▀ ████████
████████████*██▄     ▄██▄▄▄▄▄▄████████
██████████▀`  ▀██▄   ▀████████████████
████████▀`  ▄█████▌   ╙███████████████
████████▄,   ▀████ ,,,  "▀▀███████████
██████████,,,,, ╙█▄███▄▄,,,,╙▀████████
██████████████████████████████████████
██████████████████████████████████████
██████████████████████████████████████
L B X.


■                         ■                        ■                        ■                        ■                        ■                         ■
The London Block Exchange
■                         ■                        ■                        ■                        ■                        ■                         ■
.


.
.


.
WDownload OnW
[.
          ▄▄█▀
         ███▀
   ▄▄▄▄  ▀  ▄▄▄▄
 ▄███████▄██████▌
▐██████████████▌
███████████████
▐██████████████▌
 ███████████████▌
  ██████████████▌
   ▀████▀▀▀████▀
/      ▌ ▄▄▄▄ ▐
     ▄█▀████▀█▄
    ▐██████████▌
 ▄▄ ▀▀▀▀▀▀▀▀▀▀▀▀ ▄▄
▐██▌████████████▐██▌
▐██▌████████████▐██▌
▐██▌████████████▐██▌
 ▀▀ ████████████ ▀▀
    ▀██████████▀
      ▐██  ██▌
      ▐██  ██▌
]
.


LeGaulois
Copper Member
Legendary
*
Offline Offline

Activity: 2940
Merit: 4101


Top Crypto Casino


View Profile
February 05, 2018, 04:31:33 PM
Merited by nullius (1)
 #6

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?

Ledger didn't receive a "wallet attack". A vector has been discovered last month with the Google Chrome application. Nobody has been affected currently (or at least it has not been found on the web). People using the hardware just need to validate the integrity of the address. (Checking if the address is correct, like you are always supposed to do, no matter the support used).

https://bitcointalk.org/index.php?topic=2878882.msg29653349#msg29653349

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
silent17
Full Member
***
Offline Offline

Activity: 420
Merit: 119


View Profile
February 05, 2018, 04:48:49 PM
 #7

I thought hardware is kind a USB look alike and no one can open it until you say so.

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?

How can be this hardware wallet would be attack? What to do it to buy another hardware wallet its better safe than never. I would suggest as well to try a different wallet that is myetherwallet its safe too you know I cant offer you suggestion its up to you.


I would just say if you think your not safe anymore on working with that hardware wallet try to buy new one that us trezor its 2nd best to ledger.

I would not think we can recommend myetherwallet, because myetherwallet can't hold Bitcoin.
I agree with other, The OP didn't explain very well the situation about the hacking. Because I think you can't really hack bitcoin in a USB wallet without accessing the wallet itself using a primary key.
bitart
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 629


Vires in Numeris


View Profile
February 05, 2018, 10:33:13 PM
 #8

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.
It's a receive attack, means that a malware try to change the receiving address of your wallet when it shows on the screen (and changes it to a hacker's address), in order to copy and paste the hacked address when you want to receive bitcoins into your wallet. When you use the chrome bitcoin application, you can click on a small button on the screen which shows the receiving address on the Ledger Nano S device itself, so if you check the two addresses you won't lose any bitcoin. So it's not a malware that completly wipes your hardware wallet but just hijacks the bitcoins you want to receive into the wallet.
tokexchain
Member
**
Offline Offline

Activity: 144
Merit: 10


View Profile
February 05, 2018, 10:37:23 PM
 #9

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.
It's a receive attack, means that a malware try to change the receiving address of your wallet when it shows on the screen (and changes it to a hacker's address), in order to copy and paste the hacked address when you want to receive bitcoins into your wallet. When you use the chrome bitcoin application, you can click on a small button on the screen which shows the receiving address on the Ledger Nano S device itself, so if you check the two addresses you won't lose any bitcoin. So it's not a malware that completly wipes your hardware wallet but just hijacks the bitcoins you want to receive into the wallet.

Very nice and helpful explanation - in these days of exploits and data breaches we all need to be aware of the potential and very real attacks - there are going on around all day and close to us digitally. Be wary and stay safe.
Cryptoshops
Member
**
Offline Offline

Activity: 271
Merit: 10


View Profile
February 05, 2018, 10:39:01 PM
 #10

He is talking about this

https://cointelegraph.com/news/newly-discovered-vulnerability-in-all-ledger-hardware-wallets-puts-user-funds-at-risk
Dvach
Member
**
Offline Offline

Activity: 111
Merit: 11


View Profile
February 05, 2018, 10:46:28 PM
 #11

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.
It's a receive attack, means that a malware try to change the receiving address of your wallet when it shows on the screen (and changes it to a hacker's address), in order to copy and paste the hacked address when you want to receive bitcoins into your wallet. When you use the chrome bitcoin application, you can click on a small button on the screen which shows the receiving address on the Ledger Nano S device itself, so if you check the two addresses you won't lose any bitcoin. So it's not a malware that completly wipes your hardware wallet but just hijacks the bitcoins you want to receive into the wallet.
Only Ledger Nano S device is affected by this malware? What about Ledger Blue? As far as I understand, it uses same app, but Ledger claims it's the most secure device. What about Trezor or KeepKey? Is there any similar malware targeted on hacking Trezor or KeepKey?
bitart
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 629


Vires in Numeris


View Profile
February 06, 2018, 09:29:27 PM
 #12

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.
It's a receive attack, means that a malware try to change the receiving address of your wallet when it shows on the screen (and changes it to a hacker's address), in order to copy and paste the hacked address when you want to receive bitcoins into your wallet. When you use the chrome bitcoin application, you can click on a small button on the screen which shows the receiving address on the Ledger Nano S device itself, so if you check the two addresses you won't lose any bitcoin. So it's not a malware that completly wipes your hardware wallet but just hijacks the bitcoins you want to receive into the wallet.
Only Ledger Nano S device is affected by this malware? What about Ledger Blue? As far as I understand, it uses same app, but Ledger claims it's the most secure device. What about Trezor or KeepKey? Is there any similar malware targeted on hacking Trezor or KeepKey?
I have no information about the Ledger Blue. If it's using the same app in Chrome, it's possible that the malware is able to change the receiving address of the Blue as well. Anyway, it helps if you double check the address on the device's screen as well, in the Chrome app. If you're using it with MEW, I've no info about the possibility of chechking the address on the device if you're connected to MEW.
carlisle1
Hero Member
*****
Offline Offline

Activity: 2744
Merit: 541

Campaign Management?"Hhampuz" is the Man


View Profile
March 03, 2018, 05:18:02 AM
 #13

I thought hardware is kind a USB look alike and no one can open it until you say so.

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?

How can be this hardware wallet would be attack? What to do it to buy another hardware wallet its better safe than never. I would suggest as well to try a different wallet that is myetherwallet its safe too you know I cant offer you suggestion its up to you.


I would just say if you think your not safe anymore on working with that hardware wallet try to buy new one that us trezor its 2nd best to ledger.

I would not think we can recommend myetherwallet, because myetherwallet can't hold Bitcoin.
I agree with other, The OP didn't explain very well the situation about the hacking. Because I think you can't really hack bitcoin in a USB wallet without accessing the wallet itself using a primary key.
nobody says it was BITCOIN who has been hacked,OP says the ledger wallet lol..but i cant really understand whats the mean of op about hacking the ledger whe it was in usb form,how could that be possible?can you explain further  for the benefits of all who has the same settings
BitcoinsGreat
Sr. Member
****
Offline Offline

Activity: 1022
Merit: 280


View Profile
March 25, 2018, 03:50:48 PM
 #14

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.

Yes, no one can steal your coins from your ledger wallet while it is offline but once you connect your Legder wallet to the system to move funds, a malware is designed to take all of your funds always. So there is always a risk whether be online or offline.
BillCoin
Sr. Member
****
Offline Offline

Activity: 476
Merit: 259



View Profile
March 25, 2018, 03:58:44 PM
 #15

Has anyone been affected by this and would it now be a good time to buy another hardware wallet?

Also it I've been reading where it says to press the monitor before sending and receiving to verify your address is correct is that true as well?

What the hell is going on?
What do you mean by attack is someone steal your money? Since no one can steal your bitcoins in hardware wallets without private keys so how it can happen.I hope OP will explain the real case behind ledger wallet attack.

Yes, no one can steal your coins from your ledger wallet while it is offline but once you connect your Legder wallet to the system to move funds, a malware is designed to take all of your funds always. So there is always a risk whether be online or offline.

In order to release a transaction from a ledger wallet you need to be connected to the internet.
Ledger is being split into 2 parts,one part contains the private key and has the code of signing transactions, on the other hand, the 2nd part of the ledger contains the connection to the internet is usually getting the transaction key from the offline part.
The problem was that there was a security breech so actually you could hack the ledger at the point it transferred the funds from the offline part to the online part.
Seriously security breech.
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
March 25, 2018, 04:05:25 PM
 #16

The problem was that there was a security breech so actually you could hack the ledger at the point it transferred the funds from the offline part to the online part.
Seriously security breech.

The vulnerability you are talking about was regarding a faked (malicious) receiving address being shown on the desktop application.
This is due to the fact that the software still has to run on your OS and that everything on your screen can (theoretically) be changed / compromised.

This has been fixed with a simple verification of your receiving address on the nano s screen.
Anything verified on the nano s screen can be considered as truly being generated by your nano s (and therefore being secure).

gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3015


Welt Am Draht


View Profile
March 25, 2018, 04:07:52 PM
 #17

Even if this hadn't been publicised, people should assume that whatever your computer is displaying to you can be spoofed. That's why these devices have displays to verify everything on.

If I had something like an original Nano HW1 I certainly wouldn't be using it any more.
arienna23
Full Member
***
Offline Offline

Activity: 221
Merit: 101



View Profile
March 25, 2018, 05:01:18 PM
 #18

I always double check and triple check the receiving address, even when I'm sending relatively small amounts from one of my wallets to another address I own.

Paranoia is a perfectly healthy condition when you invest in crypto.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!