Ledger On Security Vulnerability Incident: Victims Will Be Made Whole
Ledger addressed the recent security incident that took place, and fortunately, it seems that the victims will be made whole, which is terrific news. Check out the latest reports about this below. Ledger addresses securi...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Ledger addressed the recent security incident that took place, and fortunately, it seems that the victims will be made whole, which is terrific news. Check out the latest reports about this below.
Ledger addresses security vulnerabilityLedger, a hardware wallet company, has addressed a security vulnerability in its products that was recently exposed.
On December 14th, the company announced that one of its employees was targeted in a phishing attack, which allowed a malicious version of the Ledger Connect Kit to be published.
This affected users who connected to decentralized applications (DApps).
The attacker’s USDT address was frozen by Tether, the largest stablecoin issuer in the world, after the exploit, preventing much of the funds from being moved further.
Ledger has confirmed that around $600,000 in assets were impacted and has assured users that it will make them whole and prevent similar incidents from occurring in the future.
“We commit, by any way possible, including gestures of goodwill, to make sure this is done by the end of February 2024. We are already in contact with many impacted users and are actively working through the specifics with them.
We remind users that if you signed a transaction on affected DApps December 14th, 2023, best security practices would recommend revoking any authorized transactions to further reduce impact from the malicious code.”
Ledger plans to disable the option to blind-sign transactions in the future, as a response to past front-end attacks.
Blind signing allows users to skip the process of signing transactions before allowing a smart contract to interact with their wallets.
To ensure user safety, Ledger aims to prohibit this practice.
The company believes front-end attacks will continue to plague the ecosystem, and the only foolproof countermeasure is for users to always verify what they consent to on their device.
Stay tuned for more news from the crypto space.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoGazetteRelated market context
S&P brings ratings-style scrutiny to $10 billion crypto vault market as $6 million Base incident exposes risks
S&P Global is bringing ratings-style risk assessments to crypto lending vaults as the fast-growing market confronts fresh security...
Tether Celebrates 12 Years, USD₮ Surpasses 700M Users
Key Takeaways: Tether marked the 12th anniversary of the world’s largest stablecoin by market cap, USD₮. The company claims that U...
Ether is about to lose a steady buyer as Tom Lee says Bitmine will stop token purchases
Tom Lee said Bitmine will be “done stacking” once it owns 5% of ETH, setting an end date to an accumulation streak that began in m...
SecondFi offers $8 for every unrecoverable NFT lost in $21M hack
Cardano wallet firm SecondFi finally launched a recovery portal for victims of the neo-finance platform’s $21 million hack, but wi...
Cardano News: CIP-0113 Upgrade Could Change ADA Future
Good news coming from The Cardano Foundation as it launched CIP-0113 on mainnet, giving issuers of regulated stablecoins, funds, a...
OpenAI math breakthroughs raise ‘bunker mode’ alarm from Bitcoin researcher Justin Drake
OpenAI’s latest advances in mathematics have prompted a leading Ethereum researcher to warn that crypto’s core wallet security cou...