Bitcoin Forum
October 09, 2026, 02:21:01 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: Ledger hacked or vulnerable  (Read 309 times)
dkbit98 (OP)
Legendary
*
Offline

Activity: 3108
Merit: 8909



View Profile WWW
August 27, 2026, 08:33:53 PM
Merited by The Sceptical Chymist (7)
 #1

Chinese team OneKey_Anzen published a report claiming they exploied ledger vulnerability,
and they successfully reproduced a transaction replacement attack against ledger ethereum app 1.22.1.
I never liked ledger apps, especially for altcoins, and they are clearly another weak spot in bad closed source space.
It is good to see Onekey developers are actually doing some investigation.
https://x.com/ohyishi/status/2092953186193801599
https://onekey.so/anzen/

Ledger already replied they fixed this and there are no evidence of attacks happened against users.
There are 3 security bulletin reports from today and you can read their explanation:
https://donjon.ledger.com/lsb/

Even if people didn't lose coins with ledger, and I again suggesting everyone to STOP using this devices.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░▀░░░░░▀░░░░▀▀██
▄▄██████▄░▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░█░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░█░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░█░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
█████░█████
▐████▌░▐████▌
▀▀░▀█░░░█▀░▀▀
 
Charles-Tim
Legendary
*
Offline

Activity: 2422
Merit: 6585


Leading Crypto Sports Betting & Casino Platform


View Profile
August 27, 2026, 08:39:44 PM
Merited by The Sceptical Chymist (4)
 #2

I read about it today, it was about something related to ethereum. Ledger said it fixed it in version 1.22.2 before OneKey reported the vulnerability. That was what Ledger said about it.

But there are people that would have not updated their wallet.

Ledger has been one of the hardware wallets that I do not like since I join this forum because of the hardware wallet secure element.

██████████████████████████████████████████████████████████████
████████████
▀▀███████▀████████████████████████████████████████
██████████
▀██▄▄████▄██▐████▀▀███████████▀▀████████████████████
█████████
▌██▐██████▌██████▌█▐█████████████▐███████████████████
█████████
▌█████████▄▄▄██████▀▀▀▀███████▌█████▀████████████████
██████████
▄███▀███████▀▀██████▄██████████▐█▀█▄███▀▀███████████
████████████
▄▄███▀▀██▄▄▄▄██▐███▀██▄█▐█▌██▀█▄██▀██▄▄███████████
████████████████
▄▄███▀██▌███████▄█▌███████▐██▌███▀█▄██████████
██████████
▀███▄███████████▐██▌█▐████████▐██▐████▄██▀██████████
█████████
▌██▄███████████▄████▄████▄██▄██████▀▄█████▄▀█████████
█████████
▌██▀███▀▀███▄█████████████████████▄██▀▀▀▀▀█▄█████████
██████████
▄██████▄▄██████████████████████████▄▄▄▄▄▄███████████
██████████████████████████████████████████████████████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██

 🎰  🎲 ..Play Smarter.. 🏀  ⚽ ..Play Now..
Mia Chloe
Legendary
*
Online Online

Activity: 1218
Merit: 2305


Contact me for you designs...


View Profile
August 27, 2026, 09:20:19 PM
 #3

~snip
I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited. Anyways for me the bigger concern is the closed source nature of some of their software that alone is enough to make me prefer more transparent alternatives  the idea of closes source for a hardware wallet kinda sounds unsafe to me.

X-ray
Hero Member
*****
Offline

Activity: 3752
Merit: 580


Leading Crypto Sports Betting & Casino Platform


View Profile
August 28, 2026, 04:00:37 AM
 #4

~snip
I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited. Anyways for me the bigger concern is the closed source nature of some of their software that alone is enough to make me prefer more transparent alternatives  the idea of closes source for a hardware wallet kinda sounds unsafe to me.
The OneKey team reproduced by building 1.22.1 ELF, a firmware that have the vulnerability after the fix has been live, but I think it's kind of pointless?

The team said they hacked the ledger but in reality they're only building old vulnerable firmware with disclosed vulnerability.

The reproduction of transaction was to show that the race condition is really there but the fact that ledger team released fix means it's there without even the need to reproduce the attack.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
joniboini
Legendary
*
Offline

Activity: 3066
Merit: 1934


#kycfree ❎


View Profile WWW
August 28, 2026, 04:25:03 AM
 #5

The OneKey team reproduced by building 1.22.1 ELF, a firmware that have the vulnerability after the fix has been live, but I think it's kind of pointless?
I wonder if scammers will go out of their way to distribute this vulnerable firmware with DNS attack or something similar. Based on some recent supply chain attacks it's possible they'll upload malicious files and users will get tricked thinking it's a valid update. That being said though, if that's in their plan they'll probably went as far as uploading malware instead of vulnerable firmware that requires a trick or two to exploit. CMIIW.

satscraper
Legendary
*
Offline

Activity: 1610
Merit: 3022


AntiSwap.io - NO AML/KYC EXCHANGER MONITORING


View Profile
August 28, 2026, 06:22:05 AM
Last edit: August 28, 2026, 06:56:34 AM by satscraper
Merited by The Sceptical Chymist (3)
 #6

I read about it today, it was about something related to ethereum. Ledger said it fixed it in version 1.22.2 before OneKey reported the vulnerability. That was what Ledger said about it.



The ethereum app was just the first one patched,  but according to  Bulletin 023 the underlying flaw lived in shared SDK code that every app built on, not something specific exclusively to Ethereum. Ledger fixed this releasing new SDK v26.6.1, released 21 August so now the 3rd party app developers who are relevant to Ledger must react and rebuild to be on the safe side.

Synchronice
Legendary
*
Offline

Activity: 1736
Merit: 1193



View Profile
August 28, 2026, 10:20:22 AM
Merited by The Sceptical Chymist (4)
 #7

~snip
I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited. Anyways for me the bigger concern is the closed source nature of some of their software that alone is enough to make me prefer more transparent alternatives  the idea of closes source for a hardware wallet kinda sounds unsafe to me.
This vulnerability alone is not the reason why people should stop using Ledger. First of all, Ledger is partially open source but its core firmware tied to secure chip remains closed source and here is the most important part, Ledger has been lying to us that keys never leave Secure Chip. Later, they introduced Ledger Recover service, which made it clear that keys leave Secure Chip. So, basically, the most important part of their code is closed-source and they also lie to us. Basically, we don't know the code and they don't tell the truth, so it's a big no.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
_act_
Legendary
*
Offline

Activity: 1764
Merit: 2006



View Profile
August 28, 2026, 01:28:30 PM
 #8

This vulnerability alone is not the reason why people should stop using Ledger. First of all, Ledger is partially open source but its core firmware tied to secure chip remains closed source and here is the most important part, Ledger has been lying to us that keys never leave Secure Chip. Later, they introduced Ledger Recover service, which made it clear that keys leave Secure Chip. So, basically, the most important part of their code is closed-source and they also lie to us. Basically, we don't know the code and they don't tell the truth, so it's a big no.
Ledger also said the seed phrase sent to the recovery services can be given to the government if the government demanded for it. That means the coins people have on ledger, they do not have full control over it. People will always be people, they supposed to all stop using Ledger after doing all these.

When talking about privacy, Ledger is the worst that you can use. Scammers and hackers may know that you are using Ledger. But this is becoming common to other wallets.

stompix
Legendary
*
Offline

Activity: 3766
Merit: 7427



View Profile WWW
August 28, 2026, 02:57:01 PM
 #9

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited.

Someone managing to exploit a piece of software in a controlled environment doesn't mean that all the devices are vulnerable.
You still needed to have access to that device to run it, so either infect the device itself, or do so through an infected computer with specifically that kind of malware....
This is an incredibly small pool of attacks, you need to target Ledger users, Ledger users with said coin balance, be able to infect their computer point of entry or one of the apps, wait for them to actually make a transaction before they update their devices.
The moment you're able to do that you have a lot more options than just this exploit to drain a balance.





▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Yamane_Keto
Hero Member
*****
Offline

Activity: 1008
Merit: 616



View Profile WWW
August 28, 2026, 05:10:58 PM
 #10

The fact that it was reproduced is kinda a valid criticism but from what I can see ledger fixed it and there’s currently no evidence users were actually exploited.
For these attacks to succeed, the user must either download a malicious wallet application, establish a WebUSB connection, or install malware on their computer; this implies that success relies on user negligence rather than a device failure. yet exploiting these bugs remains difficult.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
X-ray
Hero Member
*****
Offline

Activity: 3752
Merit: 580


Leading Crypto Sports Betting & Casino Platform


View Profile
August 29, 2026, 01:19:29 AM
 #11

I wonder if scammers will go out of their way to distribute this vulnerable firmware with DNS attack or something similar. Based on some recent supply chain attacks it's possible they'll upload malicious files and users will get tricked thinking it's a valid update. That being said though, if that's in their plan they'll probably went as far as uploading malware instead of vulnerable firmware that requires a trick or two to exploit. CMIIW.
I doubt it's going to be that easy, the Ethereum app (1.22.1) build isn't going to be officially signed.

If I read correctly, the OneKey team only using Ledger's emulator Speculos to run the build and recreate or reproduce the attack.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
The Sceptical Chymist
Legendary
*
Offline

Activity: 4214
Merit: 7389


♻️ Automatic Exchange


View Profile
October 04, 2026, 10:37:56 AM
 #12

I think the vulnerability is definitely concerning but I wouldn't go as far as saying everyone should stop using Ledger based on this alone however I personally don't recommend using it in the first place.

No, definitely not--it's that giant Recover debacle that revealed what a scumbag company they are that seems to have died down but should never be forgotten. 

I also agree that HW devices ought to be probed for vulnerabilities, and not just Ledger either.  I'm not a coder, so I'm one of those who have to put my trust in the experts that they are looking for holes, experts within the HW wallet company and in the community--which includes competition.  I'd like to see results for some of the others on the market.  Ledger has a bright red stain on its reputation already (although it's probably still the most popular in spite of that), so they're the biggest target, but how about the others?

There are a lot of devices on the market.

░░░░▄▄████████████▄
░▄████████████████▀
▄████████████████▀▄█▄
▄███████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀░▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀░▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄░▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀░
▀████████████▀▀░░░░
 
 CCECASH 
 
    ANN THREAD    
 
      TUTORIAL      
Pmalek
Legendary
*
Offline

Activity: 3640
Merit: 9632



View Profile
October 06, 2026, 03:55:31 PM
 #13

No, definitely not--it's that giant Recover debacle that revealed what a scumbag company they are that seems to have died down but should never be forgotten. 
Don't forget: Ledger Recover users need to pay a monthly subscription to use the service. I think it's €10 a month or something like that. Users are paying the company to extract keys from their devices and send them over the internet to three third-parties somewhere. Law enforcement could then put pressure on those companies to confiscate coins if they deem it "necessary." It's the 'paying for it' that's the highest form of perversion. You pay to increase the chances of someone getting custody of your crypto, regardless if it's Ledger, law enforcement, the involved third parties or hackers/scammers.

By putting a price tag on the service, unsuspecting users may think it's some premium feature that has to be great. Why else would you need to pay for it. Roll Eyes

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
|⚽ 🏀
 
🏈 🏓
 
🎯 🥊
 
⚾ 🎾
 
⛳ 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

 ✔ G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Forsyth Jones
Legendary
*
Offline

Activity: 2044
Merit: 2303


I love Bitcoin!


View Profile WWW
October 06, 2026, 10:52:14 PM
 #14

Don't forget: Ledger Recover users need to pay a monthly subscription to use the service. I think it's €10 a month or something like that. Users are paying the company to extract keys from their devices and send them over the internet to three third-parties somewhere. Law enforcement could then put pressure on those companies to confiscate coins if they deem it "necessary." It's the 'paying for it' that's the highest form of perversion. You pay to increase the chances of someone getting custody of your crypto, regardless if it's Ledger, law enforcement, the involved third parties or hackers/scammers.

By putting a price tag on the service, unsuspecting users may think it's some premium feature that has to be great. Why else would you need to pay for it. Roll Eyes
Ledger Recover is seen as a ticking time bomb... Even though it's only activated with the user's conscious consent, who guarantees they aren't sending encrypted keys on the servers? We know the code is closed source, so neither the company can guarantee anything beyond words and marketing arguments, nor do the users themselves have any assurance that the firmware actually behaves as stated...

If Ledger truly wants to gain credibility from Bitcoiners OG users, they should make the firmware open source.

It seems they like to follow the motto: make mistakes, keep making mistakes, and they can't see an opportunity to make a mistake without diving headfirst into it............

m2017
Legendary
*
Offline

Activity: 2632
Merit: 1747


keep walking, Johnnie


View Profile
October 07, 2026, 05:04:16 AM
Merited by Pmalek (3), vapourminer (1), ABCbits (1)
 #15

Users are paying the company to extract keys from their devices and send them over the internet to three third-parties somewhere.
At a moment like that, find yourself wondering: what could possibly go wrong? ... Everything! Smiley

Law enforcement could then put pressure on those companies to confiscate coins if they deem it "necessary."
All the regulator needs to do is mandate via yet another "wonderful" bill passed "for the greater good, against everything bad, and for the well-being of citizens" - that HW manufacturer collect, store, and transmit seed-phrases, much like the requirements for KYCs and personal data collection (data that routinely gets leaked or stolen). Sound absurd? In reality, bills just as idiotic as that actually get passed.

It's the 'paying for it' that's the highest form of perversion.
Well, smokers also pay for the thing that's "killing" them. Smiley So, it's all good. Smiley

You pay to increase the chances of someone getting custody of your crypto, regardless if it's Ledger, law enforcement, the involved third parties or hackers/scammers.
To get clients to agree to this, the key is to present it in an appealing way.

By putting a price tag on the service, unsuspecting users may think it's some premium feature that has to be great. Why else would you need to pay for it. Roll Eyes
I imagine that’s precisely the "effect" ledger was counting on. In reality, in this case, ledger ought to be paying the users. Smiley Ledger owners would actually be better off staking their crypto-assets; you lose control over the assets there too, but at least you get paid some small amount of interest.

Either you pay or you get paid, but the outcome is the same: you lose control.


Ledger Recover is seen as a ticking time bomb... Even though it's only activated with the user's conscious consent, who guarantees they aren't sending encrypted keys on the servers? We know the code is closed source, so neither the company can guarantee anything beyond words and marketing arguments, nor do the users themselves have any assurance that the firmware actually behaves as stated...
And yet, someone is using Ledger Recovery (on a paid basis), right? It would be interesting to know the number of users in order to gauge the scale (of the potential threat).

If Ledger truly wants to gain credibility from Bitcoiners OG users, they should make the firmware open source.
Which hackers and malicious actors will inevitably study - using AI. They will find a vulnerability, and the Coldcard saga will repeat itself.

It seems they like to follow the motto: make mistakes, keep making mistakes, and they can't see an opportunity to make a mistake without diving headfirst into it............
As long as it makes them money, it isn't a mistake. Besides, why should we care about other's mistakes? At least, not as long as it doesn't affect us.

Every one of their customers makes a mistake by blindly trusting the Ledger Recovery feature.

Therefore, the solution is this: don't use Ledger Recovery, don't own a ledger's hardware wallets, and stay away from that company.

Pmalek
Legendary
*
Offline

Activity: 3640
Merit: 9632



View Profile
October 07, 2026, 07:33:19 AM
Merited by m2017 (1)
 #16

If Ledger truly wants to gain credibility from Bitcoiners OG users, they should make the firmware open source.
Doing it now after so many years of being closed-source isn't going to change much. Besides, you can't change things retroactively. They can make their firmware open-source now but what did the code do last year? What about five years ago or ten years ago when the Nano S was first released?

All the regulator needs to do is mandate via yet another "wonderful" bill passed "for the greater good, against everything bad, and for the well-being of citizens"
Don't forget the children. Never forget the children. Children must be safe online so it's best to KYC everyone.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
|⚽ 🏀
 
🏈 🏓
 
🎯 🥊
 
⚾ 🎾
 
⛳ 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

 ✔ G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
ABCbits
Legendary
*
Offline

Activity: 3752
Merit: 10425



View Profile
October 07, 2026, 08:27:04 AM
 #17

No, definitely not--it's that giant Recover debacle that revealed what a scumbag company they are that seems to have died down but should never be forgotten. 
Don't forget: Ledger Recover users need to pay a monthly subscription to use the service. I think it's €10 a month or something like that. Users are paying the company to extract keys from their devices and send them over the internet to three third-parties somewhere.
--snip--

Also don't forget that Ledger used to make fake/false claim private key can't leave or extracted from their device.

Quote from: ledger.com/academy/basic-basics/ledgers-bit-of-it/ledger-nano-security-made-easy
At Ledger, we offer you the best security and provide you with ownership and control over your assets. Therefore, we created the hardware wallets combined with one single app Ledger Live, to safeguard your private keys and mitigate potential risks. In short, the devices are designed so that your private keys never leave the security of the hardware, even when connecting your wallet to your smartphone or desktop.
Hi - your private keys never leave the Secure Element chip, which has never been hacked. The Secure Element is 3rd party certified, and is the same technology as used in passports and credit cards. A firmware update cannot extract the private keys from the Secure Element.

In case those link become invalid or changed, check https://web.archive.org/web/20260910154931/ledger.com/academy/basic-basics/ledgers-bit-of-it/ledger-nano-security-made-easy and https://archive.ph/CZhFl.



All the regulator needs to do is mandate via yet another "wonderful" bill passed "for the greater good, against everything bad, and for the well-being of citizens"
Don't forget the children. Never forget the children. Children must be safe online so it's best to KYC everyone.

And that's what EU currently try to do with EU Kids Act, using "kids safety" as scapegoat.

Pmalek
Legendary
*
Offline

Activity: 3640
Merit: 9632



View Profile
October 07, 2026, 03:21:07 PM
 #18

Also don't forget that Ledger used to make fake/false claim private key can't leave or extracted from their device.
Honestly, many (if not all) hardware wallet manufacturers are guilty of making that claim. They have said in one way or the other that keys and sensitive information can NEVER leave the device secure element chips. Ledger was the first and only one that we know of that built a key extraction feature into its software but that doesn't change that hardware wallets can function in a way we were told they couldn't. Build in key extraction firmware and suddenly keys are no longer safe in their enclosures.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
|⚽ 🏀
 
🏈 🏓
 
🎯 🥊
 
⚾ 🎾
 
⛳ 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

 ✔ G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Meuserna
Sr. Member
****
Offline

Activity: 391
Merit: 744


View Profile WWW
October 07, 2026, 07:25:42 PM
Merited by ABCbits (2), vapourminer (1)
 #19

Also don't forget that Ledger used to make fake/false claim private key can't leave or extracted from their device.
Honestly, many (if not all) hardware wallet manufacturers are guilty of making that claim. They have said in one way or the other that keys and sensitive information can NEVER leave the device secure element chips. Ledger was the first and only one that we know of that built a key extraction feature into its software but that doesn't change that hardware wallets can function in a way we were told they couldn't. Build in key extraction firmware and suddenly keys are no longer safe in their enclosures.

That's a huge, Huge, HUGE difference though.

Ledger gave hackers an API to extract keys from Ledger devices over the internet. It's built into every Ledger device. And I can't help assuming the trackers in Ledger's awful companion app will eventually be used by hackers to find Ledger users (Ledger Wallet, formerly known as Ledger Live).

I think that whole scheme is a time bomb waiting to go off. And when it does, we'll never know. It'll be just like what happened to ColdCard users: Hackers will spend a long time gathering as many seed phrases from Ledger wallets as they can before they empty them en masse. Hackers could already be gathering Ledger seed phrases as we speak.

That being said... I definitely agree that any hardware wallet can be susceptible to hacks. This is one of the reasons I stopped using hardware wallets that save the seed (or the wallet) on the device. I switched to airgapped & stateless self custody instead: SeedSigner/ShieldSigner, Krux, Kern.

Airgapped: Can't be reached over the internet.
Stateless: The seed can't be extracted from the device (because nothing is saved on the device).

And with ShieldSigner, Krux and Kern, you can encrypt the SeedQR, which means even if somebody finds it, all they found is a QR code that scans as empty (because it's encrypted).

Pmalek
Legendary
*
Offline

Activity: 3640
Merit: 9632



View Profile
October 08, 2026, 07:34:02 AM
 #20

That's a huge, Huge, HUGE difference though.

Ledger gave hackers an API to extract keys from Ledger devices over the internet.
I am not disputing that. Ledger has committed corporate suicide multiple times now. If it was a smaller player in the wider hardware wallet industry, they would have been long gone by now. But I am saying that many companies have used this false marketing, describing hardware wallets and secure element chips as enclosures from where nothing can leak and no malware can get access to. Ledger shattered those 'illusions.' The SE can leak everything it's told to leak in the firmware.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
|⚽ 🏀
 
🏈 🏓
 
🎯 🥊
 
⚾ 🎾
 
⛳ 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

 ✔ G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!