Ledger Under Fire After Questions Arise Over Security Measures
Crypto’s flagship cold storage tool, Ledger, is taking heat from the crypto community this week following a Reddit post from a Ledger co-founder that suggested that external companies could have exposure to user seed phr...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Crypto’s flagship cold storage tool, Ledger, is taking heat from the crypto community this week following a Reddit post from a Ledger co-founder that suggested that external companies could have exposure to user seed phrases on an opt-in basis. The situation is far from ‘cut and dry’ and has led to substantial dialogue throughout crypto communities around the degree of security that Ledger owes it’s users.
Let’s take a look at both angles of the argument.
Ledger Lunacy: Where It All StartedThe genesis of this started with a new firmware update over the past day, leading to quick question marks about the implications from the udpate. A Reddit post on subreddit r/ledgerwallet late on Monday / early on Tuesday this week is what set it all off, courtesy of a thread titled “Is there a backdoor? Yes or No.”
The Reddit poster asked in the body of the post:
An official answet from ledger would be very much appreciated. Also because the alternative (typing the three parts of the seed for the three custodians) goes against the number one rule of never typing your seed in a connected device. This silence on how this “recovery” works is the worst response. Customers appreciate transparency.
The post opened the floodgates to speculation, and responses from Ledger co-founder Nicolas Bacca (u/BTChip) didn’t field encouragement for Ledger users. Bacca provided several responses to user concerns throughout the thread, including this reply on the thread itself:
There’s no backdoor and I obviously can’t prove it (because it’s not possible to prove a negative) – let’s just say that you’re already using the device agreeing with the fact that Ledger cannot update the firmware without your consent – it’s the same mechanism for Recover, which is locked behind ownership of your device, knowledge of your pin, and finally your consent on device.
There’ll be more information published shortly describing how the service works – the tldr is that no single company knows your seed if you decide to use it. If you don’t want to use it there’s no consequence whatsoever in your previous experience of the device.
In all, users are seemingly left still trying to answer one dying question: Can a Ledger device expose a seed phrase?
The Big Picture: Back & Forth DialogueWhile the meltdown continued on Reddit, parlayed with new subreddit threads on the ‘hot’ page like “consider moving to a different cold wallet,” “How to kill your business,” and many more, Crypto Twitter also took hold of the situation. Resident Crypto Twitter dev Foobar amplified the situation further:
Stop using Ledger hardware wallets. Migrate away from them immediately. They’ve shown nothing but gross incompetence and wild misunderstanding of their own purpose. And now they’ve publicly admitted to intentionally backdooring their own proprietary hardware. Stop using Ledger pic.twitter.com/LLFFUsOW4y
— foobar (@0xfoobar) May 16, 2023
Not all were in agreement though, as another noteworthy dev, Udi Wertheimer, posted his disagreement. Wertheimer replied that the post was “irresponsible hyperbole” and that “Ledger remains as safe to use today as it was yesterday. For MOST people it is the easiest hardware solution to recommend.”
In all, it is right and to-be-expected in the crypto community that firms like Ledger face immense scrutiny: the integrity of the industry has a meaningful degree at stake over the security and integrity of the largest cold storage provide in the business. While it is likely that some community members are losing their head too quickly, Ledger will likely continue to face pressures to increase transparency around the degrees of access to wallet keys.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on NewsBTCRelated market context
Losses Top $115M In Coldcard Bitcoin Hack: Galaxy Research
Bitcoin Magazine Losses Top $115M In Coldcard Bitcoin Hack: Galaxy Research New data from Galaxy Research shows that $115 million...
Bitcoin purchases halted after data breach puts 250,000 crypto users at risk
Israel’s largest regulated cryptocurrency broker, Bits of Gold, is investigating a data breach that potentially exposed the person...
Bits of Gold Breach May Expose 200,000 Crypto Users, But Funds Remain Safe Online
Key Takeaways: A data breach at Bits of Gold could affect up to 200,000 customers. No exposure of customer funds, crypto assets, p...
SafePal Data Breach Exposes 39,798 Crypto Customers, Wallet Keys Remain Secure
Key Takeaways: About 39,798 users’ personal and purchase information were disclosed via a flaw in an order tracking plugin, accord...
Half of Aave’s debt sits in just 9% of positions built around one Ethereum correlation trade
Galaxy's Aug. 7 snapshot of Aave V3 Core found 19,073 loans on the protocol after applying standard filters. Fewer than 9% of thos...
Ethereum developers propose privacy changes for next major upgrade
Ethereum's proposed privacy upgrades could redefine user anonymity and regulatory compliance, impacting blockchain transparency an...