Ledger On Security Vulnerability Incident: Victims Will Be Made Whole
Ledger addressed the recent security incident that took place, and fortunately, it seems that the victims will be made whole, which is terrific news. Check out the latest reports about this below. Ledger addresses securi...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Ledger addressed the recent security incident that took place, and fortunately, it seems that the victims will be made whole, which is terrific news. Check out the latest reports about this below.
Ledger addresses security vulnerabilityLedger, a hardware wallet company, has addressed a security vulnerability in its products that was recently exposed.
On December 14th, the company announced that one of its employees was targeted in a phishing attack, which allowed a malicious version of the Ledger Connect Kit to be published.
This affected users who connected to decentralized applications (DApps).
The attacker’s USDT address was frozen by Tether, the largest stablecoin issuer in the world, after the exploit, preventing much of the funds from being moved further.
Ledger has confirmed that around $600,000 in assets were impacted and has assured users that it will make them whole and prevent similar incidents from occurring in the future.
“We commit, by any way possible, including gestures of goodwill, to make sure this is done by the end of February 2024. We are already in contact with many impacted users and are actively working through the specifics with them.
We remind users that if you signed a transaction on affected DApps December 14th, 2023, best security practices would recommend revoking any authorized transactions to further reduce impact from the malicious code.”
Ledger plans to disable the option to blind-sign transactions in the future, as a response to past front-end attacks.
Blind signing allows users to skip the process of signing transactions before allowing a smart contract to interact with their wallets.
To ensure user safety, Ledger aims to prohibit this practice.
The company believes front-end attacks will continue to plague the ecosystem, and the only foolproof countermeasure is for users to always verify what they consent to on their device.
Stay tuned for more news from the crypto space.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoGazetteRelated market context
Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Key Takeaways: Through a leak in the software of its shipping partner ShipMonk, Trezor disclosed private information related to ap...
CyberWallet users have until Aug. 15 before crypto withdrawals become a smart contract recovery job
Crypto company Cyber is telling CyberWallet and Cyber Passkey Wallet users to move their assets ahead of an Aug. 15 shutdown that...
With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line
On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyer...
Multicoin exits the $1.65 billion Solana treasury company it helped launch eight months ago
Multicoin Capital has exited its disclosed stake in Forward Industries, the largest Solana treasury company, according to SEC fili...
Another public company abandons Bitcoin playbook after treasury volatility drove $22 million loss
KULR Technology Group has exited Bitcoin mining, repaid its Coinbase debt, and begun selling its BTC holdings as the battery techn...
Binance to restrict transactions involving HTX, 10 other crypto platforms
Binance said it will stop processing transactions for involving 11 crypto platforms, including HTX, which was recently listed in t...