Ledger Hardware Wallet to Issue Exploit Fix to Prevent Users from Sending BTC on Accident

2020-8-6 21:24

According to a blog published by Mo Nokhbeh, a crypto software researcher, the Ledger Wallet app is in danger of exploitation due to a vulnerability that has persisted on the platform since 2019. According to Mo, a user can send Bitcoin (BTC) instead of other Bitcoin forks such as the BTC testnets, Litecoin, Bitcoin Cash etc. without their knowledge if even if they had selected the ‘forks’.

To use the Ledger hardware wallet, a user must install the corresponding app on to the USB drive allowing users to hold different types of digital currencies. However, only one app is able to be open at a time to ensure security and total isolation of the apps.

An issue arises with BTC and its corresponding forks for example if your Litecoin app is open and live and you’d wish to send LTC, the wallet will prompt a confirmation of a Bitcoin transaction while the interface presents it as an LTC transaction to a Litecoin address. If you accept the confirmation, a fully valid BTC transaction will be sent out of your wallet instead of the cheaper altcoin forks.

Read More >> Data Breach at Popular Hardware Crypto Wallet Ledger Affects Million; Trezor Fires Shots

Interactions with Ledger

Mo has been vocal to the Ledger team on the vulnerability of their platform, but claims his cries fell on deaf years with the issue persisting for the past year and a half. In a response posted on Decrypt, a spokesperson from Ledger said the delays were mainly due to the communications channels the security researcher used. The spokesperson said,

“The researcher contacted us through many means—mainly Twitter DMs. The appropriate medium for bug bounty remains the dedicated email address bounty@ledger.fr. Due to this, our point of view on this timeline differs, and we are genuinely sorry for the miscommunication.”

However, Nokhbeh denies the claims saying the only time he sent a Twitter DM was recently in June 2020 after a number of failed tries through the official channels.

Read More>> Crypto Hardware Wallet Ledger: ‘Funds are Safe' After ‘BigSpender' Vulnerability Found

Solution to the Ledger App vulnerability

In a statement focusing on the possible exploits, Ledger said the vulnerability arose as a tradeoff between security and usability especially for the Bitcoin network. While the external security of the wallets remain solid, Ledger allows Bitcoin forks/derivatives that follow the same derivation path as the top crypto to derive public keys or sign Bitcoin transactions. It reads,

“Some BTC forks use the same derivation path as BTC. If we prevent these forks from using the BTC derivation path, this would simply prevent users from using the Ledger Nano S/X with these forks.”

The statement further states the solution to the issue has been released in a new update warning users when their intended and confirmation transactions do not match.

We’d like to thank the researcher for helping us make our Ledger Nanos more secure. A new version of the Bitcoin app will be released today, with an update that will display a warning and prompt for confirmation when an unexpected path is used–therefore solving this issue.

— Ledger (@Ledger) August 5, 2020

origin »

Bitcoin (BTC) на Currencies.ru

$ 75493.86 (-1.33%)
Объем 24H $50.361b
Изменеия 24h: -6.01 %, 7d: -11.28 %
Cегодня L: $74685.18 - H: $77014.76
Капитализация $1498.452b Rank 1
Цена в час новости $ 11746.28 (542.7%)

bitcoin btc ledger according wallet persisted cash

bitcoin btc → Результатов: 126


BTC, ETH price prediction as traders buy Bitcoin Pepe

Bitcoin hovers at $84k, after its worst quarter in three years. Ethereum has also struggled with downside pressure as it trades around $1.8k. What does the BTC and ETH price outlook mean for alt and meme coins, including Bitcoin Pepe? The crypto market continues to experience turbulence, with major assets like Bitcoin (BTC) and Ethereum […] The post BTC, ETH price prediction as traders buy Bitcoin Pepe appeared first on CoinJournal.

2025-4-1 15:14


Фото:

El Salvador Buys The Dip Scooping Up 5 BTC — Despite IMF Pressure To Back Off Bitcoin

El Salvador bought a further 5 BTC for its national reserve, worth roughly $415,000, as the top crypto nosedived to sub-$83,000 on Monday, reversing Sunday’s price rally to $95,000. Continuing A Bitcoin Purchase Streak According to the El Salvador National Bitcoin Office, the Central American nation purchased 5 BTC, which is four more than its […]

2025-3-5 21:15


Bitcoin Market Dominance Faces a Challenge as This AI Altcoin is Set for 22,000% Gains

Many were left stunned after seeing Bitcoin (BTC) achieve milestone upon milestone but witnessing altcoins like Ethereum (ETH), Ripple (XRP), and Cardano (ADA) fail to pump by a meaningful amount. Now, after three straight months of Bitcoin (BTC) dominance, it seems the altcoin market is ready to push back with a major inflow of investments [...]

2025-2-12 02:00